3.3
CVSSv2

CVE-2022-22333

Published: 23/02/2022 Updated: 02/03/2022
CVSS v2 Base Score: 3.3 | Impact Score: 2.9 | Exploitability Score: 6.5
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 295
Vector: AV:A/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 and IBM Sterling External Authentication Server are vulnerable a buffer overflow, due to the Jetty based GUI in the Secure Zone not properly validating the sizes of the form content and/or HTTP headers submitted. A local attacker positioned inside the Secure Zone could submit a specially crafted HTTP request to disrupt service. IBM X-Force ID: 219133.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ibm sterling external authentication server 3.4.3.2

ibm sterling external authentication server 6.0.2.0

ibm sterling external authentication server 6.0.3.0

ibm sterling secure proxy 3.4.3.2

ibm sterling secure proxy 6.0.2

ibm sterling secure proxy 6.0.3.0