CVE-2024-51453: IBM Sterling Secure Proxy directory traversal
IBM Sterling Secure Proxy 6.2.0.0 through 6.2.0.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
Other sources
IBM Sterling Secure Proxy could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-51453?
CVE-2024-51453 is a medium severity vulnerability that allows directory traversal in IBM Sterling Secure Proxy.
How do I fix CVE-2024-51453?
To fix CVE-2024-51453, you should upgrade IBM Sterling Secure Proxy to version 6.2.0.2 or later.
What systems are affected by CVE-2024-51453?
CVE-2024-51453 affects IBM Sterling Secure Proxy versions 6.2.0.0 through 6.2.0.1.
Can CVE-2024-51453 be exploited remotely?
Yes, CVE-2024-51453 can be exploited remotely by sending specially crafted URL requests to the affected system.
What potential impact does CVE-2024-51453 have?
If exploited, CVE-2024-51453 could allow an attacker to view arbitrary files on the system, leading to information disclosure.