CVE-2026-78415: IBM Sterling Secure Proxy is vulnerable to multiple issues
IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to perform UI spoofing and phishing attacks due to improper neutralization of user-supplied HTML markup.
Other sources
IBM Sterling Secure Proxy could allow a remote authenticated attacker to perform UI spoofing and phishing attacks due to improper neutralization of user-supplied HTML markup.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Sterling Secure Proxyto a version that resolves this vulnerability.Fixed in 6.2.1.3 - Compensating control
If immediate upgrading is not possible, limit access to Sterling Secure Proxy’s web/UI to only necessary, trusted users/networks until the upgrade to 6.2.1.3 is completed.
Event History
Frequently Asked Questions
Which deployments are affected?
IBM Sterling Secure Proxy versions 6.2.0.0 through 6.2.1.2 are affected.
What does an attacker need to exploit this issue?
The attacker must be remote and authenticated. No user interaction is required for exploitation according to the provided vector.
What is the likely impact?
An authenticated attacker could use insufficient neutralization of user-supplied HTML to conduct UI spoofing and phishing attacks. The vulnerability is rated medium severity with low confidentiality and integrity impact, and no availability impact.