Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-15533
HistoryFeb 25, 2022 - 12:00 a.m.

IBM Sterling Secure Proxy缓冲区溢出漏洞

2022-02-2500:00:00
China National Vulnerability Database
www.cnvd.org.cn
17
ibm
sterling secure proxy
buffer overflow
security vulnerability
file transfers
dmz
multi-factor authentication
ssl
firewall
protocol checking
denial-of-service attack

EPSS

0

Percentile

5.2%

IBM Sterling Secure Proxy, an IBM application proxy for securing file transfers in an organization’s unprotected zone (DMZ), secures trusted zones with multi-factor authentication, SSL session interruption, inbound firewall vulnerability patching, protocol checking, and other controls.IBM Sterling Secure Proxy A security vulnerability exists in versions 6.0.3.0, 6.0.2.0, and 3.4.3.2 and IBM Sterling External Authentication Server. The vulnerability stems from a lack of valid validation of the submitted form content size by the Jetty-based GUI in Secure Zone. An attacker could exploit the vulnerability to launch a denial-of-service attack by submitting a specially crafted HTTP request.

EPSS

0

Percentile

5.2%

Related for CNVD-2022-15533