Known vulnerabilities in IBM Sterling Secure Proxy - page 2
Vendor:
IBM Corporation
Software:
IBM Sterling Secure Proxy
Software CPE:
cpe:2.3:a:ibm_corporation:ibm_sterling_secure_proxy:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
108
Public exploits:
7
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
6.1.0.4
6.2.1.2.iFix02
6.2.1.2
6.1.0.0
6.2.1.0
6.2.0.2
6.1.0.2
6.1.0.3
6.2.0.3
6.2.1.1
6.2.0.1
6.2.0.0
6.2.0.1 iFix 02
6.1.0.1 iFix 03
6.0.3.1 iFix 03
6.2.0.1 iFix 01
6.1.0.1 iFix 02
6.2.0.0 ifix 01
6.1.0.1
6.0.3.1
6.1.0 iFix 03
6.0.3 iFix 11
6.0.3 iFix 06
6.0.3 iFix 08
6.0.3 iFix 05
6.0.3 iFix 07
6.0.3
6.0.2
3.4.3.2
Vulnerabilities (108)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU117436 - Allocation of Resources Without Limits or Throttling CVE-2025-8916 |
CWE-770 | Medium | 6.1.0.3, 6.2.0.3, 6.2.1.1 | 21.10.2025 |
SB2025102223 SB2025102241 SB2025102248 and 35 more |
||
| #VU109903 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2024-51453 |
CWE-22 | Low | 6.2.0.1 iFix 02 | 28.05.2025 |
SB2025052822 |
||
| #VU109902 - Use of Weak Hash CVE-2024-38341 |
CWE-328 | High | 6.0.3.1 iFix 03, 6.1.0.1 iFix 03, 6.2.0.1 iFix 02 | 28.05.2025 |
SB2025052821 |
||
| #VU102064 - Incorrect Permission Assignment for Critical Resource CVE-2024-38337 |
CWE-732 | High | 6.0.3.1, 6.1.0.1, 6.2.0.0 ifix 01 | 30.12.2024 |
SB2024123088 |
||
| #VU101635 - Improper input validation CVE-2024-41783 |
CWE-20 | High | 6.0.3.1, 6.1.0.1 | 11.12.2024 |
SB2024121124 |
||
| #VU101344 - Integer overflow CVE-2024-10917 |
CWE-190 | Low | 6.0.3.1 iFix 03, 6.1.0.1 iFix 03, 6.2.0.1 iFix 02 | 09.12.2024 |
SB2024120927 SB2024120928 SB2024120929 and 66 more |
||
| #VU98644 - Improper input validation CVE-2024-21235 |
CWE-20 | Medium | 6.0.3.1 iFix 03, 6.1.0.1 iFix 03, 6.2.0.1 iFix 02 | 15.10.2024 |
SB20241015214 SB20241015215 SB20241015216 and 129 more |
||
| #VU98645 - Improper input validation CVE-2024-21210 |
CWE-20 | Low | 6.0.3.1 iFix 03, 6.1.0.1 iFix 03, 6.2.0.1 iFix 02 | 15.10.2024 |
SB20241015215 SB2024101668 SB2024101672 and 122 more |
||
| #VU98647 - Improper input validation CVE-2024-21208 |
CWE-20 | Low | 6.0.3.1 iFix 03, 6.1.0.1 iFix 03, 6.2.0.1 iFix 02 | 15.10.2024 |
SB20241015214 SB20241015215 SB20241015216 and 139 more |
||
| #VU98648 - Improper input validation CVE-2024-21217 |
CWE-20 | Low | 6.0.3.1 iFix 03, 6.1.0.1 iFix 03, 6.2.0.1 iFix 02 | 15.10.2024 |
SB20241015214 SB20241015215 SB20241015216 and 142 more |
||
| #VU97226 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2024-27267 |
CWE-362 | Medium | 6.0.3.1, 6.1.0.1 | 12.09.2024 |
SB2024091291 SB2024091292 SB2024091618 and 57 more |
||
| #VU94557 - Improper input validation CVE-2024-21140 |
CWE-20 | Medium | 6.0.3.1, 6.1.0.1 | 18.07.2024 |
SB20240718154 SB20240718155 SB20240718156 and 119 more |
||
| #VU94558 - Improper input validation CVE-2024-21144 |
CWE-20 | Low | 6.0.3.1, 6.1.0.1 | 18.07.2024 |
SB20240718154 SB20240718155 SB20240718192 and 114 more |
||
| #VU94559 - Improper input validation CVE-2024-21131 |
CWE-20 | Low | 6.0.3.1, 6.1.0.1 | 18.07.2024 |
SB20240718154 SB20240718155 SB20240718156 and 135 more |
||
| #VU94560 - Improper input validation CVE-2024-21138 |
CWE-20 | Low | 6.0.3.1, 6.1.0.1 | 18.07.2024 |
SB20240718154 SB20240718155 SB20240718156 and 117 more |
||
| #VU91984 - Permissions, Privileges, and Access Controls CVE-2024-3933 |
CWE-264 | Low | 6.0.3.1, 6.1.0.1 | 12.06.2024 |
SB2024061213 SB20240613101 SB20240613102 and 29 more |
||
| #VU89218 - Resource exhaustion CVE-2024-29857 |
CWE-400 | Medium | 6.1.0.1 iFix 02, 6.2.0.1 iFix 01 | 07.05.2024 |
SB2024050731 SB2024061019 SB20240611170 and 69 more |
||
| #VU87128 - Improper input validation CVE-2024-25016 |
CWE-20 | Medium | 6.0.3.1, 6.1.0.1, 6.2.0.0 ifix 01 | 05.03.2024 |
SB2024030526 SB2024030614 SB2024031536 and 7 more |
||
| #VU86808 - Resource exhaustion CVE-2024-22201 |
CWE-400 | Medium | 6.0.3.1, 6.1.0.1 | 26.02.2024 |
SB2024022652 SB2024030711 SB2024030845 and 43 more |
||
| #VU58198 - Exposure of sensitive information to an unauthorized actor CVE-2021-40690 |
CWE-200 | Medium | 6.0.3.1, 6.1.0.1 | 16.11.2021 |
SB2021111622 SB2021111712 SB2022012032 and 37 more |
Showing elements 21 - 40 out of 108