PT-2016-6757 · Ibm · Ibm Sterling Secure Proxy
Published
2016-10-06
·
Updated
2016-11-28
·
CVE-2016-6026
CVSS v3.1
5.3
Medium
| Vector | AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Sterling Secure Proxy (SSP) versions 3.4.2 through 3.4.2.0 iFix 7
IBM Sterling Secure Proxy (SSP) versions 3.4.3 through 3.4.3.0 iFix 0
Description
The issue in the Configuration Manager of IBM Sterling Secure Proxy allows man-in-the-middle attackers to obtain sensitive information via an HTTP method that is neither GET nor POST.
Recommendations
For IBM Sterling Secure Proxy (SSP) versions 3.4.2 through 3.4.2.0 iFix 7, apply iFix 8 to resolve the issue.
For IBM Sterling Secure Proxy (SSP) versions 3.4.3 through 3.4.3.0 iFix 0, apply iFix 1 to resolve the issue.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Sterling Secure Proxy