VendorsIBMsterling_secure_proxyall versions
Vulnerabilities

IBM Sterling Secure Proxy

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

31CVEs
CVE-2024-41783
IBM Sterling Secure Proxy improper input validation
Published 2025-01-19 · Analyzed
9.1EPSS 0.007
CVE-2024-38337
IBM Sterling Secure Proxy improper input validation
Published 2025-01-19 · Analyzed
9.1EPSS 0.005
CVE-2020-4462
IBM Sterling External Authentication Server 6.0.1, 6.0.0, 2.4.3.2, and 2.4.2 and IBM Sterling Secure Proxy 6.0.1, 6.0.0, 3.4.3, and 3.4.2 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 181482.
Published 2020-07-16 · Modified
8.2EPSS 0.032
CVE-2021-29725
IBM Secure External Authentication Server 2.4.3.2, 6.0.1, 6.0.2 and IBM Secure Proxy 3.4.3.2, 6.0.1, 6.0.2 could allow a remote user to consume resources causing a denial of service due to a resource leak.
Published 2021-07-15 · Modified
7.5EPSS 0.029
CVE-2016-6023
Directory traversal vulnerability in the Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows remote attackers to read arbitrary files via a crafted URL.
Published 2016-10-06 · Modified
7.5EPSS 0.021
CVE-2022-22336
IBM Sterling External Authentication Server and IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 could allow a remote user to consume resources causing a denial of service due to a resource leak. IBM X-Force ID: 219395.
Published 2022-02-23 · Modified
7.5EPSS 0.020
CVE-2021-29723
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-ForceID: 201100.
Published 2021-08-30 · Modified
7.5EPSS 0.009
CVE-2021-29722
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 201095.
Published 2021-08-30 · Modified
7.5EPSS 0.009
CVE-2024-41784
IBM Sterling Secure Proxy directory traversal
Published 2024-11-15 · Analyzed
7.5EPSS 0.007
CVE-2024-51453
IBM Sterling Secure Proxy directory traversal
Published 2025-05-28 · Analyzed
7.5EPSS 0.005
CVE-2022-34361
IBM Sterling Secure Proxy information disclosure
Published 2022-12-06 · Modified
7.5EPSS 0.004
CVE-2024-38341
IBM Sterling Secure Proxy information disclosure
Published 2025-05-28 · Analyzed
7.5EPSS 0.002
CVE-2021-29749
IBM Secure External Authentication Server 6.0.2 and IBM Secure Proxy 6.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 201777.
Published 2021-07-15 · Modified
6.5EPSS 0.008
CVE-2022-22333
IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 and IBM Sterling External Authentication Server are vulnerable a buffer overflow, due to the Jetty based GUI in the Secure Zone not properly validating the sizes of the form content and/or HTTP headers submitted. A local attacker positioned inside the Secure Zone could submit a specially crafted HTTP request to disrupt service. IBM X-Force ID: 219133.
Published 2022-02-23 · Modified
6.5EPSS 0.006
CVE-2016-6027
The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information or modify data by leveraging use of HTTP.
Published 2016-10-06 · Modified
6.1EPSS 0.008
CVE-2023-47699
IBM Secure Proxy cross-site scripting
Published 2024-03-15 · Modified
6.1EPSS 0.003
CVE-2023-47162
IBM Secure Proxy cross-site scripting
Published 2024-03-15 · Modified
6.1EPSS 0.003
CVE-2016-6025
The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows remote attackers to obtain access by leveraging an unattended workstation to conduct a post-logoff session-reuse attack involving a modified URL.
Published 2016-10-06 · Modified
5.9EPSS 0.005
CVE-2023-47147
IBM Secure Proxy file manipulation
Published 2024-03-15 · Modified
5.9EPSS 0.004
CVE-2023-32338
IBM Sterling Secure Proxy information disclosure
Published 2023-09-04 · Modified
5.5EPSS 0.002
CVE-2022-35720
IBM Sterling External Authentication Server information disclosure
Published 2023-02-08 · Modified
5.5EPSS 0.001
CVE-2023-46182
IBM Secure Proxy cross-site scripting
Published 2024-03-15 · Modified
5.4EPSS 0.004
CVE-2021-29726
IBM Sterling Secure Proxy 6.0.3 and IBM Secure External Authentication Server 6.0.3 does not properly ensure that a certificate is actually associated with the host due to improper validation of certificates. IBM X-Force ID: 201104.
Published 2022-05-17 · Modified
5.3EPSS 0.009
CVE-2016-6026
The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows man-in-the-middle attackers to obtain sensitive information via an HTTP method that is neither GET nor POST.
Published 2016-10-06 · Modified
5.3EPSS 0.004
CVE-2013-0519
IBM Sterling Secure Proxy 3.2.0 and 3.3.01 before 3.3.01.23 Interim Fix 1, 3.4.0 before 3.4.0.6 Interim Fix 1, and 3.4.1 before 3.4.1.7 provides web-server version data in (1) an unspecified page title and (2) an unspecified HTTP header field, which allows remote attackers to obtain potentially sensitive information by reading a version string.
Published 2013-05-10 · Modified
5.0EPSS 0.012
CVE-2021-29728
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 201160.
Published 2021-08-30 · Modified
4.9EPSS 0.010
CVE-2022-34362
IBM Sterling Secure Proxy HOST header injection
Published 2023-02-08 · Modified
4.6EPSS 0.004
CVE-2013-0518
IBM Sterling Secure Proxy 3.2.0 and 3.3.01 before 3.3.01.23 Interim Fix 1, 3.4.0 before 3.4.0.6 Interim Fix 1, and 3.4.1 before 3.4.1.7 does not refuse to be rendered in different-origin frames, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.
Published 2013-05-10 · Modified
4.3EPSS 0.008
CVE-2023-46179
IBM Secure Proxy information disclosure
Published 2024-03-15 · Modified
4.3EPSS 0.003
CVE-2013-0520
IBM Sterling Secure Proxy 3.2.0 and 3.3.01 before 3.3.01.23 Interim Fix 1, 3.4.0 before 3.4.0.6 Interim Fix 1, and 3.4.1 before 3.4.1.7 allows remote authenticated users to obtain sensitive Java stack-trace information by providing invalid input data.
Published 2013-05-10 · Modified
4.0EPSS 0.013
CVE-2023-46181
IBM Secure Proxy information disclosure
Published 2024-03-15 · Modified
4.0EPSS 0.002