CVE-2024-41784CWE-32

IBM Sterling Secure Proxy directory traversal

High · published November 15, 2024

CVSS v3.1
7.5
EPSS
1%
Percentile
49.0
In the wild
Unconfirmed
What it is

IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, and 6.1.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot dot" sequences (/.../) to view arbitrary files on the system.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00653 · 49.0th percentile
Weakness
CWE-32 · Path Traversal: '...' (Triple Dot)
Published
2024-11-15T15:40Z
EPSS history
Timeline
  • 15 NOV 15:40Z
    IBM Sterling Secure Proxy directory traversal
    cvelistv5