CVE-2024-38337: IBM Sterling Secure Proxy improper input validation
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker to retrieve or alter sensitive information contents due to incorrect permission assignments.
Other sources
IBM Sterling Secure Proxy could allow an unauthorized attacker to retrieve or alter sensitive information contents due to incorrect permission assignments.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38337?
CVE-2024-38337 is considered a medium severity vulnerability due to the potential for unauthorized information retrieval or alteration.
How do I fix CVE-2024-38337?
To fix CVE-2024-38337, you need to apply the relevant patches provided by IBM for your affected version of Sterling Secure Proxy.
Which versions are affected by CVE-2024-38337?
CVE-2024-38337 affects IBM Sterling Secure Proxy versions 6.0.0.0 through 6.0.3.0, 6.1.0.0, and 6.2.0.0.
What type of attacks can exploit CVE-2024-38337?
CVE-2024-38337 can be exploited by unauthorized attackers aiming to retrieve or alter sensitive information due to incorrect permission assignments.
Is there a workaround for CVE-2024-38337 while patches are being applied?
Currently, no specific workaround is recommended for CVE-2024-38337, so applying the patches is the best course of action to mitigate risk.