First published: Tue Jul 13 2021(Updated: )
IBM Secure External Authentication Server 6.0.2 and IBM Secure Proxy 6.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 201777.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Secure External Authentication Server | =6.0.2 | |
IBM Secure Proxy | =6.0.2 | |
IBM Sterling Secure Proxy | =6.0.2 | |
IBM Secure External Authentication Server | <=6.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-29749.
The severity of CVE-2021-29749 is medium.
IBM Secure External Authentication Server 6.0.2 and IBM Secure Proxy 6.0.2 are affected by CVE-2021-29749.
CVE-2021-29749 may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
You can apply the patch provided by IBM to fix CVE-2021-29749.