VendorsIBMsterling_secure_proxy6.0.3.0
Vulnerabilities

IBM Sterling Secure Proxy 6.0.3.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2022-22336
IBM Sterling External Authentication Server and IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 could allow a remote user to consume resources causing a denial of service due to a resource leak. IBM X-Force ID: 219395.
Published 2022-02-23 · Modified
7.5EPSS 0.020
CVE-2024-41784
IBM Sterling Secure Proxy directory traversal
Published 2024-11-15 · Analyzed
7.5EPSS 0.007
CVE-2022-22333
IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 and IBM Sterling External Authentication Server are vulnerable a buffer overflow, due to the Jetty based GUI in the Secure Zone not properly validating the sizes of the form content and/or HTTP headers submitted. A local attacker positioned inside the Secure Zone could submit a specially crafted HTTP request to disrupt service. IBM X-Force ID: 219133.
Published 2022-02-23 · Modified
6.5EPSS 0.006