Sterling Secure Proxy
IBM · 31 CVEs
IBM Sterling Secure Proxy is vulnerable to multiple issues
Sep 14, 2026
IBM Sterling Secure Proxy is vulnerable to multiple issues
Sep 14, 2026
IBM Sterling Secure Proxy directory traversal
May 28, 2025
IBM Sterling Secure Proxy information disclosure
May 28, 2025
IBM Sterling Secure Proxy improper input validation
Jan 19, 2025
IBM Sterling Secure Proxy improper input validation
Jan 19, 2025
IBM Sterling Secure Proxy directory traversal
Nov 15, 2024
IBM Secure Proxy information disclosure
Mar 15, 2024
IBM Secure Proxy cross-site scripting
Mar 15, 2024
IBM Secure Proxy file manipulation
Mar 15, 2024
IBM Secure Proxy information disclosure
Mar 15, 2024
IBM Secure Proxy cross-site scripting
Mar 15, 2024
IBM Secure Proxy cross-site scripting
Mar 15, 2024
IBM Sterling Secure Proxy information disclosure
Sep 5, 2023
IBM Sterling Secure Proxy information disclosure
Sep 4, 2023
IBM Sterling Secure Proxy HOST header injection
Feb 8, 2023
IBM Sterling External Authentication Server information disclosure
Feb 8, 2023
IBM Sterling Secure Proxy information disclosure
Dec 6, 2022
IBM Sterling Secure Proxy 6.0.3 and IBM Secure External Authentication Server 6.0.3 does not properly ensure that a cer…
May 17, 2022
IBM Sterling External Authentication Server and IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 could allow a r…
Feb 23, 2022
IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 and IBM Sterling External Authentication Server are vulnerable…
Feb 23, 2022
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 contains hard-coded credentials, such as a password or cry…
Aug 30, 2021
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that co…
Aug 30, 2021
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that co…
Aug 30, 2021
IBM Secure External Authentication Server 6.0.2 and IBM Secure Proxy 6.0.2 is vulnerable to server-side request forgery…
Jul 15, 2021
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-75792 | IBM Sterling Secure Proxy is vulnerable to multiple issues | MEDIUM | 0.36% | Sep 14, 2026 |
| CVE-2026-78415 | IBM Sterling Secure Proxy is vulnerable to multiple issues | MEDIUM | 0.31% | Sep 14, 2026 |
| CVE-2024-51453 | IBM Sterling Secure Proxy directory traversal | HIGH | 0.52% | May 28, 2025 |
| CVE-2024-38341 | IBM Sterling Secure Proxy information disclosure | HIGH | 0.22% | May 28, 2025 |
| CVE-2024-41783 | IBM Sterling Secure Proxy improper input validation | CRITICAL | 0.67% | Jan 19, 2025 |
| CVE-2024-38337 | IBM Sterling Secure Proxy improper input validation | CRITICAL | 0.48% | Jan 19, 2025 |
| CVE-2024-41784 | IBM Sterling Secure Proxy directory traversal | HIGH | 0.65% | Nov 15, 2024 |
| CVE-2023-46181 | IBM Secure Proxy information disclosure | MEDIUM | 0.18% | Mar 15, 2024 |
| CVE-2023-47699 | IBM Secure Proxy cross-site scripting | MEDIUM | 0.35% | Mar 15, 2024 |
| CVE-2023-47147 | IBM Secure Proxy file manipulation | MEDIUM | 0.41% | Mar 15, 2024 |
| CVE-2023-46179 | IBM Secure Proxy information disclosure | MEDIUM | 0.28% | Mar 15, 2024 |
| CVE-2023-47162 | IBM Secure Proxy cross-site scripting | MEDIUM | 0.35% | Mar 15, 2024 |
| CVE-2023-46182 | IBM Secure Proxy cross-site scripting | MEDIUM | 0.36% | Mar 15, 2024 |
| CVE-2023-29261 | IBM Sterling Secure Proxy information disclosure | MEDIUM | 0.17% | Sep 5, 2023 |
| CVE-2023-32338 | IBM Sterling Secure Proxy information disclosure | MEDIUM | 0.19% | Sep 4, 2023 |
| CVE-2022-34362 | IBM Sterling Secure Proxy HOST header injection | MEDIUM | 0.36% | Feb 8, 2023 |
| CVE-2022-35720 | IBM Sterling External Authentication Server information disclosure | MEDIUM | 0.12% | Feb 8, 2023 |
| CVE-2022-34361 | IBM Sterling Secure Proxy information disclosure | HIGH | 0.39% | Dec 6, 2022 |
| CVE-2021-29726 | IBM Sterling Secure Proxy 6.0.3 and IBM Secure External Authentication Server 6.0.3 does not properly ensure that a certificate is actually associated with the… | MEDIUM | 0.87% | May 17, 2022 |
| CVE-2022-22336 | IBM Sterling External Authentication Server and IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 could allow a remote user to consume resources causing… | HIGH | 2.00% | Feb 23, 2022 |
| CVE-2022-22333 | IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 and IBM Sterling External Authentication Server are vulnerable a buffer overflow, due to the Jetty base… | MEDIUM | 0.58% | Feb 23, 2022 |
| CVE-2021-29728 | IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its ow… | MEDIUM | 0.99% | Aug 30, 2021 |
| CVE-2021-29723 | IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly… | HIGH | 0.92% | Aug 30, 2021 |
| CVE-2021-29722 | IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly… | HIGH | 0.92% | Aug 30, 2021 |
| CVE-2021-29749 | IBM Secure External Authentication Server 6.0.2 and IBM Secure Proxy 6.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated… | MEDIUM | 0.83% | Jul 15, 2021 |
Showing 1 to 25 of 31 CVEs