First published: Thu Mar 14 2024(Updated: )
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 270974.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Secure Proxy | <=6.0.3 | |
IBM Secure Proxy | <=6.1.0 | |
IBM Sterling Secure Proxy | =6.0.3 | |
IBM Sterling Secure Proxy | =6.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-47699 is classified as a cross-site scripting vulnerability that can lead to credentials disclosure.
To fix CVE-2023-47699, apply the latest security patches provided by IBM for versions 6.0.3 and 6.1.0 of Sterling Secure Proxy.
CVE-2023-47699 affects IBM Sterling Secure Proxy versions 6.0.3 and 6.1.0.
CVE-2023-47699 can allow attackers to execute arbitrary JavaScript code in the Web UI, compromising user sessions and potentially exposing sensitive data.
Organizations using IBM Sterling Secure Proxy versions 6.0.3 and 6.1.0 are at risk due to CVE-2023-47699.