Learn about CVE-2020-4763 affecting IBM Sterling File Gateway versions 6.0.0.0 through 6.0.3.2 and 2.2.0.0 through 2.2.6.5. Understand the impact, technical details, and mitigation steps.
IBM Sterling File Gateway versions 6.0.0.0 through 6.0.3.2 and 2.2.0.0 through 2.2.6.5 are affected by a vulnerability that allows attackers to obtain cookie values, potentially compromising user security.
Understanding CVE-2020-4763
This CVE involves a lack of secure attribute setting on authorization tokens or session cookies in IBM Sterling File Gateway, leading to potential cookie value exposure.
What is CVE-2020-4763?
The Impact of CVE-2020-4763
Technical Details of CVE-2020-4763
Vulnerability Description
The vulnerability in IBM Sterling File Gateway allows attackers to intercept cookie values by exploiting the lack of secure attribute setting on authorization tokens or session cookies.
Affected Systems and Versions
Exploitation Mechanism
Attackers can obtain cookie values by sending malicious http:// links to users or planting them on visited sites to intercept the insecure cookies.
Mitigation and Prevention
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates