First published: Thu Aug 31 2023(Updated: )
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow a local user with specific information about the system to obtain privileged information due to inadequate memory clearing during operations. IBM X-Force ID: 252139.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sterling External Authentication Server | =6.0.3.0 | |
IBM Sterling External Authentication Server | =6.1.0 | |
IBM Sterling External Authentication Server | <=6.0.3 | |
IBM Sterling External Authentication Server | <=6.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security issue in IBM Sterling Secure Proxy is CVE-2023-29261.
The severity rating for vulnerability CVE-2023-29261 is medium, with a severity value of 5.1.
The affected software in this vulnerability is IBM Sterling Secure Proxy version 6.0.3 and 6.1.0, as well as IBM Sterling External Authentication Server version 6.0.3.0 and 6.1.0.
To fix the vulnerability in IBM Sterling Secure Proxy, you can apply the patch provided by IBM through the following links: [Link 1](http://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7EOther+software&product=ibm%2FOther+software%2FSterling+External+Authentication+Server&release=6.0.2.0&platform=All&function=all) and [Link 2](http://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7EOther+software&product=ibm%2FOther+software%2FSterling+External+Authentication+Server&release=6.0.2.0&platform=All&function=all).
The Common Weakness Enumeration (CWE) ID associated with this vulnerability is CWE-922.