CVE-2016-6026: Infoleak
The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows man-in-the-middle attackers to obtain sensitive information via an HTTP method that is neither GET nor POST.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6026?
CVE-2016-6026 is classified as a medium severity vulnerability due to the potential for man-in-the-middle attacks.
How do I fix CVE-2016-6026?
To remediate CVE-2016-6026, it's recommended to update IBM Sterling Secure Proxy to version 3.4.2.0 iFix 8 or 3.4.3.0 iFix 1 or later.
What versions of IBM Sterling Secure Proxy are affected by CVE-2016-6026?
CVE-2016-6026 affects IBM Sterling Secure Proxy versions 3.4.2.0 prior to iFix 8 and versions 3.4.3.0 prior to iFix 1.
What types of attacks can exploit CVE-2016-6026?
CVE-2016-6026 can be exploited by man-in-the-middle attackers to gain access to sensitive information.
Is CVE-2016-6026 fixed in the latest version of IBM Sterling Secure Proxy?
Yes, CVE-2016-6026 is fixed in the latest versions 3.4.2.0 iFix 8 and 3.4.3.0 iFix 1.