PT-2016-6758 · Ibm · Ibm Sterling Secure Proxy
Publicado
2016-10-06
·
Atualizado
2016-11-28
·
CVE-2016-6027
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Sterling Secure Proxy (SSP) versions 3.4.2 through 3.4.2.0 iFix 7
IBM Sterling Secure Proxy (SSP) versions 3.4.3 through 3.4.3.0 iFix 0
Description
The issue concerns the Configuration Manager in IBM Sterling Secure Proxy (SSP) which does not enable the HSTS protection mechanism. This makes it easier for remote attackers to obtain sensitive information or modify data by leveraging the use of HTTP.
Recommendations
For IBM Sterling Secure Proxy (SSP) versions 3.4.2 through 3.4.2.0 iFix 7, apply iFix 8 to enable HSTS protection.
For IBM Sterling Secure Proxy (SSP) versions 3.4.3 through 3.4.3.0 iFix 0, apply iFix 1 to enable HSTS protection.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Sterling Secure Proxy