CVE-2026-75792
- EPSS 0.28%
- Veröffentlicht 14.09.2026 20:57:02
- Zuletzt bearbeitet 16.09.2026 19:24:44
IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to view administrative user interface components due to client-side authorization bypass.
CVE-2026-78415
- EPSS 0.18%
- Veröffentlicht 14.09.2026 20:56:09
- Zuletzt bearbeitet 16.09.2026 19:24:58
IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to perform UI spoofing and phishing attacks due to improper neutralization of user-supplied HTML markup.
CVE-2024-51453
- EPSS 0.47%
- Veröffentlicht 28.05.2025 15:22:39
- Zuletzt bearbeitet 09.06.2025 18:58:08
IBM Sterling Secure Proxy 6.2.0.0 through 6.2.0.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
CVE-2024-38341
- EPSS 0.21%
- Veröffentlicht 28.05.2025 15:21:00
- Zuletzt bearbeitet 09.06.2025 18:57:54
IBM Sterling Secure Proxy 6.0.0.0 through 6.0.3.1, 6.1.0.0 through 6.1.0.0, and 6.2.0.0 through 6.2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
CVE-2024-41783
- EPSS 0.67%
- Veröffentlicht 19.01.2025 15:15:21
- Zuletzt bearbeitet 25.07.2025 20:38:34
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inject commands into the underlying operating system due to improper validation of a specified type of input.
CVE-2024-38337
- EPSS 0.48%
- Veröffentlicht 19.01.2025 15:15:19
- Zuletzt bearbeitet 25.07.2025 20:38:37
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker to retrieve or alter sensitive information contents due to incorrect permission assignments.
CVE-2024-41784
- EPSS 0.64%
- Veröffentlicht 15.11.2024 16:15:34
- Zuletzt bearbeitet 20.11.2024 14:35:10
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, and 6.1.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot dot" sequences (/.../) to view a...
CVE-2023-47699
- EPSS 0.35%
- Veröffentlicht 15.03.2024 16:15:08
- Zuletzt bearbeitet 21.11.2024 08:30:41
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure w...
CVE-2023-47147
- EPSS 0.42%
- Veröffentlicht 15.03.2024 16:15:08
- Zuletzt bearbeitet 21.11.2024 08:29:51
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow an attacker to overwrite a log message under specific conditions. IBM X-Force ID: 270598.
CVE-2023-46181
- EPSS 0.18%
- Veröffentlicht 15.03.2024 16:15:07
- Zuletzt bearbeitet 21.11.2024 08:28:01
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 269686.