CVE-2021-29749: SSRF
IBM Secure External Authentication Server 6.0.2 and IBM Secure Proxy 6.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 201777.
Other sources
IBM Sterling Secure Proxy is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-29749.
What is the severity of CVE-2021-29749?
The severity of CVE-2021-29749 is medium.
Which products are affected by CVE-2021-29749?
IBM Secure External Authentication Server 6.0.2 and IBM Secure Proxy 6.0.2 are affected by CVE-2021-29749.
What is the risk of CVE-2021-29749?
CVE-2021-29749 may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
How can I fix CVE-2021-29749?
You can apply the patch provided by IBM to fix CVE-2021-29749.