CVE-2024-38337
critical · 9.1IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker to retrieve or alter sensitive information contents due to incorrect permission assignments.
9.1
CVSS
0.5%
EPSS (exploit prob.)
41st
EPSS percentile
2025-01-19
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-732
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | sterling_secure_proxy | >= 6.0.0.0, < 6.0.3.1 |
| ibm | sterling_secure_proxy | 6.1.0.0 |
| ibm | sterling_secure_proxy | 6.2.0.0 |
| ibm | aix | all versions |
| ibm | linux_on_ibm_z | all versions |
| linux | linux_kernel | all versions |
| microsoft | windows | all versions |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2024-38337