CVE-2024-41784: IBM Sterling Secure Proxy directory traversal
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, and 6.1.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot dot" sequences (/.../) to view arbitrary files on the system.
Other sources
IBM Sterling Secure Proxy could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot dot" sequences (/.../) to view arbitrary files on the system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41784?
CVE-2024-41784 has a critical severity rating due to its potential for remote exploitation and access to arbitrary files.
How do I fix CVE-2024-41784?
To fix CVE-2024-41784, upgrade to IBM Sterling Secure Proxy version 6.1.0.1 or apply the latest patches provided by IBM.
What systems are affected by CVE-2024-41784?
CVE-2024-41784 affects IBM Sterling Secure Proxy versions 6.0.0.0 to 6.0.3.0 and 6.1.0.0.
Can CVE-2024-41784 be exploited remotely?
Yes, CVE-2024-41784 can be exploited remotely by sending specially crafted URL requests.
What type of vulnerability is CVE-2024-41784?
CVE-2024-41784 is a directory traversal vulnerability that allows attackers to view arbitrary files on the system.