PT-2024-10280 · Ibm · Ibm Sterling Secure Proxy

CVE-2024-38337

·

Published

2024-06-13

·

Updated

2025-01-23

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions IBM Sterling Secure Proxy versions 6.0.0.0 through 6.2.0.0
Description The issue is related to incorrect permission assignments for a critical resource in the IBM Sterling Secure Proxy. This could allow an unauthorized attacker to retrieve or alter sensitive information contents.
Recommendations For IBM Sterling Secure Proxy versions 6.0.0.0 through 6.2.0.0, update to a version that correctly assigns permissions for critical resources to prevent unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00686
CVE-2024-38337

Affected Products

Ibm Sterling Secure Proxy