First published: Tue Jul 13 2021(Updated: )
IBM Secure External Authentication Server 2.4.3.2, 6.0.1, 6.0.2 and IBM Secure Proxy 3.4.3.2, 6.0.1, 6.0.2 could allow a remote user to consume resources causing a denial of service due to a resource leak.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Secure External Authentication Server | =2.4.3.2 | |
IBM Secure External Authentication Server | =6.0.1 | |
IBM Secure External Authentication Server | =6.0.2 | |
IBM Secure Proxy | =3.4.3.2 | |
IBM Secure Proxy | =6.0.1 | |
IBM Secure Proxy | =6.0.2 | |
IBM AIX | ||
Linux Linux kernel | ||
Microsoft Windows | ||
Oracle Solaris | ||
All of | ||
Any of | ||
IBM Secure External Authentication Server | =2.4.3.2 | |
IBM Secure External Authentication Server | =6.0.1 | |
IBM Secure External Authentication Server | =6.0.2 | |
IBM Sterling Secure Proxy | =3.4.3.2 | |
IBM Sterling Secure Proxy | =6.0.1 | |
IBM Sterling Secure Proxy | =6.0.2 | |
Any of | ||
IBM AIX | ||
Linux Linux kernel | ||
Microsoft Windows | ||
Oracle Solaris | ||
IBM Secure Proxy | <=6.0.2 | |
IBM Secure Proxy | <=6.0.1 | |
IBM Sterling Secure Proxy | <=3.4.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-29725.
The title of the vulnerability is 'IBM Sterling Secure Proxy could allow a remote user to consume resources causing a denial of service.'
The severity of CVE-2021-29725 is high with a severity value of 7.5.
IBM Secure External Authentication Server versions 2.4.3.2, 6.0.1, 6.0.2 and IBM Secure Proxy versions 3.4.3.2, 6.0.1, 6.0.2 are affected by CVE-2021-29725.
To fix the vulnerability, apply the patches provided by IBM. The patch URLs are available in the reference links.