CVE-2025-2827
BaseFortify
Publication date: 2025-07-08
Last updated on: 2025-08-02
Assigner: IBM Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| linux | linux_kernel | From 5.15.160 (inc) to 5.16 (inc) |
| ibm | sterling_file_gateway | From 6.0.0.0 (inc) to 6.1.2.7_1 (exc) |
| ibm | sterling_file_gateway | From 6.2.0.0 (inc) to 6.2.0.5 (exc) |
| ibm | aix | * |
| microsoft | windows | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-548 | The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in IBM Sterling File Gateway versions 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 allows an authenticated user to disclose sensitive installation directory information. This information disclosure could potentially be leveraged to carry out further attacks against the system.
How can this vulnerability impact me? :
The impact of this vulnerability is that an authenticated user could gain access to sensitive installation directory information, which might be used to facilitate additional attacks on the system. The CVSS base score of 4.3 indicates a low to medium severity impact, primarily affecting confidentiality without impacting integrity or availability.