5.3

CVE-2016-6026

The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows man-in-the-middle attackers to obtain sensitive information via an HTTP method that is neither GET nor POST.

Data is provided by the National Vulnerability Database (NVD)
IbmSterling Secure Proxy Version3.4.2.0
IbmSterling Secure Proxy Version3.4.2.0 Updateifix1
IbmSterling Secure Proxy Version3.4.2.0 Updateifix2
IbmSterling Secure Proxy Version3.4.2.0 Updateifix3
IbmSterling Secure Proxy Version3.4.2.0 Updateifix4
IbmSterling Secure Proxy Version3.4.2.0 Updateifix5
IbmSterling Secure Proxy Version3.4.2.0 Updateifix6
IbmSterling Secure Proxy Version3.4.2.0 Updateifix7
IbmSterling Secure Proxy Version3.4.3.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.181
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.3 1.6 3.6
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 2.9 5.5 2.9
AV:A/AC:M/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.