CVE-2024-38337
IBM Sterling Secure Proxy improper input validation
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.1EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
19 Jan 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker to retrieve or alter sensitive information contents due to incorrect permission assignments.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
IBM · Sterling Secure ProxyWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →