CVE-2024-38341

MEDIUM

IBM Sterling Secure Proxy <6.2.0.1 - Info Disclosure

Title source: llm

Description

IBM Sterling Secure Proxy 6.0.0.0 through 6.0.3.1, 6.1.0.0 through 6.1.0.0, and 6.2.0.0 through 6.2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

Scores

CVSS v3 5.9
EPSS 0.0003
EPSS Percentile 7.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-326 CWE-328
Status published

Affected Products (1)

ibm/sterling_secure_proxy < 6.0.3.1

Timeline

Published May 28, 2025
Tracked Since Feb 18, 2026