Impact
IBM Sterling Secure Proxy versions 6.2.0.0 through 6.2.1.2 allow a remote authenticated attacker to view administrative user interface components because client‑side authorization checks are bypassed of the system, but it exposes configuration and management data that should normally be protected.
Affected Systems
The affected product is IBM Sterling Secure Proxy. Versions 6.2.0.0 through 6.2.1.2 are vulnerable. Version 6.2.1.26.2.1.3 and later contain the fix and are recommended for use.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate impact. EPSS is less than 1%, suggesting a very low probability of exploitation. The vulnerability is not listed in CISA KEV. Attack requires valid authentication; once authenticated, an attacker can retrieve admin UI components, which could assist in information gathering. The overall risk depends on the availability of privileged credentials and the exposure of the administrative interface.
OpenCVE Enrichment