CVE-2016-6027
MEDIUMIBM Sterling Secure Proxy <3.4.2.0-3.4.3.0 - Info Disclosure
Title source: llmDescription
The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information or modify data by leveraging use of HTTP.
Scores
CVSS v3
6.1
EPSS
0.0024
EPSS Percentile
47.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
published
Affected Products (10)
ibm/sterling_secure_proxy
ibm/sterling_secure_proxy
ibm/sterling_secure_proxy
ibm/sterling_secure_proxy
ibm/sterling_secure_proxy
ibm/sterling_secure_proxy
ibm/sterling_secure_proxy
ibm/sterling_secure_proxy
ibm/sterling_secure_proxy
n/a/n/a
Timeline
Published
Oct 06, 2016
Tracked Since
Feb 18, 2026