Description
IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to view administrative user interface components due to client-side authorization bypass.
Published: 2026-09-14
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to administrative interface components via client‑side authorization bypass
Action: Patch
AI Analysis

Impact

IBM Sterling Secure Proxy versions 6.2.0.0 through 6.2.1.2 allow a remote authenticated attacker to view administrative user interface components because client‑side authorization checks are bypassed of the system, but it exposes configuration and management data that should normally be protected.

Affected Systems

The affected product is IBM Sterling Secure Proxy. Versions 6.2.0.0 through 6.2.1.2 are vulnerable. Version 6.2.1.26.2.1.3 and later contain the fix and are recommended for use.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate impact. EPSS is less than 1%, suggesting a very low probability of exploitation. The vulnerability is not listed in CISA KEV. Attack requires valid authentication; once authenticated, an attacker can retrieve admin UI components, which could assist in information gathering. The overall risk depends on the availability of privileged credentials and the exposure of the administrative interface.

Generated by OpenCVE AI on September 17, 2026 at 20:02 UTC.

Remediation

Vendor Solution

ProductAffected Version(s)Fixed-in Version(s)RemediationIBM Sterling Secure Proxy6.2.0.0 - 6.2.1.26.2.1.3 Fix Central https://www.ibm.com/support/fixcentral/swg/selectFixes IBM strongly advises upgrading as soon as possible.


OpenCVE Recommended Actions

  • Upgrade IBM Sterling Secure Proxy to version 6.2.1.26.2.1.3 or later.
  • Restrict network access to the administrative interface to trusted internal networks only.
  • Enforce strict role‑based access control so that only necessary accounts have administrative privileges.

Generated by OpenCVE AI on September 17, 2026 at 20:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to view administrative user interface components due to client-side authorization bypass.
Title IBM Sterling Secure Proxy is vulnerable to multiple issues
First Time appeared Ibm
Ibm sterling Secure Proxy
Weaknesses CWE-285
CPEs cpe:2.3:a:ibm:sterling_secure_proxy:6.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_secure_proxy:6.2.1.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm sterling Secure Proxy
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Ibm Sterling Secure Proxy
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T17:31:47.585Z

Reserved: 2026-08-18T07:26:14.065Z

Link: CVE-2026-75792

cve-icon Vulnrichment

Updated: 2026-09-15T17:26:55.161Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T21:17:25.720

Modified: 2026-09-16T19:24:44.153

Link: CVE-2026-75792

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:00:16Z

Weaknesses