5.9

CVE-2016-6025

The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows remote attackers to obtain access by leveraging an unattended workstation to conduct a post-logoff session-reuse attack involving a modified URL.

Data is provided by the National Vulnerability Database (NVD)
IbmSterling Secure Proxy Version3.4.2.0
IbmSterling Secure Proxy Version3.4.2.0 Updateifix1
IbmSterling Secure Proxy Version3.4.2.0 Updateifix2
IbmSterling Secure Proxy Version3.4.2.0 Updateifix3
IbmSterling Secure Proxy Version3.4.2.0 Updateifix4
IbmSterling Secure Proxy Version3.4.2.0 Updateifix5
IbmSterling Secure Proxy Version3.4.2.0 Updateifix6
IbmSterling Secure Proxy Version3.4.2.0 Updateifix7
IbmSterling Secure Proxy Version3.4.3.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.2% 0.396
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.9 2.5 3.4
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P