CVE-2024-41783: IBM Sterling Secure Proxy improper input validation
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inject commands into the underlying operating system due to improper validation of a specified type of input.
Other sources
IBM Sterling Secure Proxy could allow a privileged user to inject commands into the underlying operating system due to improper validation of a specified type of input.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41783?
CVE-2024-41783 is considered a high-severity vulnerability due to its potential for command injection by a privileged user.
How do I fix CVE-2024-41783?
To remediate CVE-2024-41783, apply the patches available for affected versions of IBM Sterling Secure Proxy.
Which versions of IBM Sterling Secure Proxy are affected by CVE-2024-41783?
CVE-2024-41783 affects IBM Sterling Secure Proxy versions 6.0.0.0 to 6.0.3.0, 6.1.0.0, and 6.2.0.0.
What types of systems are at risk from CVE-2024-41783?
Systems running vulnerable versions of IBM Sterling Secure Proxy with privileged user access are at risk from CVE-2024-41783.
Is user authentication required to exploit CVE-2024-41783?
Yes, a privileged user authentication is required to exploit the command injection vulnerability in CVE-2024-41783.