CVE-2023-29261: IBM Sterling Secure Proxy information disclosure
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow a local user with specific information about the system to obtain privileged information due to inadequate memory clearing during operations. IBM X-Force ID: 252139.
Other sources
IBM Sterling Secure Proxy could allow a local user with specific information about the system to obtain privileged information due to inadequate memory clearing during operations.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue in IBM Sterling Secure Proxy?
The vulnerability ID for this security issue in IBM Sterling Secure Proxy is CVE-2023-29261.
What is the severity rating for vulnerability CVE-2023-29261?
The severity rating for vulnerability CVE-2023-29261 is medium, with a severity value of 5.1.
What is the affected software in this vulnerability?
The affected software in this vulnerability is IBM Sterling Secure Proxy version 6.0.3 and 6.1.0, as well as IBM Sterling External Authentication Server version 6.0.3.0 and 6.1.0.
How can I fix the vulnerability in IBM Sterling Secure Proxy?
To fix the vulnerability in IBM Sterling Secure Proxy, you can apply the patch provided by IBM through the following links: [Link 1](http://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7EOther+software&product=ibm%2FOther+software%2FSterling+External+Authentication+Server&release=6.0.2.0&platform=All&function=all) and [Link 2](http://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7EOther+software&product=ibm%2FOther+software%2FSterling+External+Authentication+Server&release=6.0.2.0&platform=All&function=all).
What is the Common Weakness Enumeration (CWE) ID associated with this vulnerability?
The Common Weakness Enumeration (CWE) ID associated with this vulnerability is CWE-922.