PT-2016-6758 · Ibm · Ibm Sterling Secure Proxy

Publicado

2016-10-06

·

Atualizado

2016-11-28

·

CVE-2016-6027

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions IBM Sterling Secure Proxy (SSP) versions 3.4.2 through 3.4.2.0 iFix 7 IBM Sterling Secure Proxy (SSP) versions 3.4.3 through 3.4.3.0 iFix 0
Description The issue concerns the Configuration Manager in IBM Sterling Secure Proxy (SSP) which does not enable the HSTS protection mechanism. This makes it easier for remote attackers to obtain sensitive information or modify data by leveraging the use of HTTP.
Recommendations For IBM Sterling Secure Proxy (SSP) versions 3.4.2 through 3.4.2.0 iFix 7, apply iFix 8 to enable HSTS protection. For IBM Sterling Secure Proxy (SSP) versions 3.4.3 through 3.4.3.0 iFix 0, apply iFix 1 to enable HSTS protection.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-6027

Produtos afetados

Ibm Sterling Secure Proxy