CVE-2024-41783
critical · 9.1IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inject commands into the underlying operating system due to improper validation of a specified type of input.
9.1
CVSS
0.7%
EPSS (exploit prob.)
50th
EPSS percentile
2025-01-19
Published
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-77
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | sterling_secure_proxy | >= 6.0.0.0, < 6.0.3.1 |
| ibm | sterling_secure_proxy | 6.1.0.0 |
| ibm | sterling_secure_proxy | 6.2.0.0 |
| ibm | aix | all versions |
| ibm | linux_on_ibm_z | all versions |
| linux | linux_kernel | all versions |
| microsoft | windows | all versions |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2024-41783