PT-2024-10280 · Ibm · Ibm Sterling Secure Proxy

Published

2024-06-13

·

Updated

2025-01-23

·

CVE-2024-38337

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions IBM Sterling Secure Proxy versions 6.0.0.0 through 6.2.0.0
Description The issue is related to incorrect permission assignments for a critical resource in the IBM Sterling Secure Proxy. This could allow an unauthorized attacker to retrieve or alter sensitive information contents.
Recommendations For IBM Sterling Secure Proxy versions 6.0.0.0 through 6.2.0.0, update to a version that correctly assigns permissions for critical resources to prevent unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Weakness Enumeration

Related Identifiers

BDU:2025-00686
CVE-2024-38337

Affected Products

Ibm Sterling Secure Proxy