CVE-2016-6026
06.10.2016, 10:59
The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows man-in-the-middle attackers to obtain sensitive information via an HTTP method that is neither GET nor POST.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | sterling_secure_proxy | 3.4.2.0 |
ibm | sterling_secure_proxy | 3.4.2.0:ifix1 |
ibm | sterling_secure_proxy | 3.4.2.0:ifix2 |
ibm | sterling_secure_proxy | 3.4.2.0:ifix3 |
ibm | sterling_secure_proxy | 3.4.2.0:ifix4 |
ibm | sterling_secure_proxy | 3.4.2.0:ifix5 |
ibm | sterling_secure_proxy | 3.4.2.0:ifix6 |
ibm | sterling_secure_proxy | 3.4.2.0:ifix7 |
ibm | sterling_secure_proxy | 3.4.3.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration