CVE-2016-6025: Medium severity ibm sterling secure proxy vulnerability
The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows remote attackers to obtain access by leveraging an unattended workstation to conduct a post-logoff session-reuse attack involving a modified URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6025?
CVE-2016-6025 has a medium severity level as it allows session-reuse attacks post user logoff.
How do I fix CVE-2016-6025?
To fix CVE-2016-6025, upgrade to IBM Sterling Secure Proxy version 3.4.2.0 iFix 8 or 3.4.3.0 iFix 1 or later.
What versions of IBM Sterling Secure Proxy are affected by CVE-2016-6025?
CVE-2016-6025 affects IBM Sterling Secure Proxy versions prior to 3.4.2.0 iFix 8 and 3.4.3.0 iFix 1.
What type of attack is described in CVE-2016-6025?
CVE-2016-6025 describes a post-logoff session-reuse attack that exploits an unattended workstation.
Can CVE-2016-6025 be exploited remotely?
Yes, CVE-2016-6025 can be exploited remotely by attackers leveraging an unattended workstation.