CVE-2026-75792: IBM Sterling Secure Proxy is vulnerable to multiple issues
IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to view administrative user interface components due to client-side authorization bypass.
Other sources
IBM Sterling Secure Proxy could allow a remote authenticated attacker to view administrative user interface components due to client-side authorization bypass.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Sterling Secure Proxyto a version that resolves this vulnerability.Fixed in 6.2.1.3 - Compensating control
Temporarily restrict access to the administrative UI components to trusted users/IPs until the IBM Sterling Secure Proxy upgrade to 6.2.1.3 is completed, to reduce exposure from the client-side authorization bypass.
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker must be authenticated to IBM Sterling Secure Proxy. The issue affects versions 6.2.0.0 through 6.2.1.2.
What access could an attacker gain?
An authenticated attacker could view administrative user interface components through a client-side authorization bypass. The provided information indicates confidentiality impact only; it does not indicate modification or availability impact.