Description
IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to perform UI spoofing and phishing attacks due to improper neutralization of user-supplied HTML markup.
Published: 2026-09-14
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: UI Spoofing and Phishing via stored XSS
Action: Patch Now
AI Analysis

Impact

IBM Sterling Secure Proxy versions 6.2.0.0 through 6.2.1.2 allow a remote authenticated attacker to conduct UI spoofing and phishing attacks by using improperly neutralized user-supplied HTML markup. The flaw manifests as a stored cross-site scripting vulnerability that injects malicious HTML into the application’s interface, which can appear authentic to users. Attackers can use this injection to trick users into providing credentials or to deliver malware. The vulnerable products are IBM Sterling Secure Proxy in release versions 6.2.0.0 up to 6.2.1.2. All installations within that range are affected, and the fix is incorporated in version 6.2.1.26.2.1.3 and later. The CVSS score of 5.4 indicates moderate risk because an attacker must first authenticate to the system. EPSS is reported as less than 1 %, and the vulnerability is not listed in CISA KEV. Exploitation requires the attacker to log in and then inject malicious HTML, which is rendered in the UI and can lead to credential compromise or malware delivery.

Affected Systems

IBM Sterling Secure Proxy 6.2.0.0 to 6.2.1.2 are vulnerable; the issue is resolved in 6.2.1.26.2.1.3 and later.

Risk and Exploitability

The CVSS score of 5.4 reflects a moderate threat primarily due to the authentication prerequisite. EPSS is below 1 %, and the vulnerability is not captured in the CISA KEV catalog. Attacking paths involve an authorized user injecting HTML that the application renders, enabling phishing and potential credential theft. Although the impact is confined to UI manipulation, the possibility of credential compromise warrants timely remediation.

Generated by OpenCVE AI on September 17, 2026 at 19:26 UTC.

Remediation

Vendor Solution

ProductAffected Version(s)Fixed-in Version(s)RemediationIBM Sterling Secure Proxy6.2.0.0 - 6.2.1.26.2.1.3 Fix Central https://www.ibm.com/support/fixcentral/swg/selectFixes IBM strongly advises upgrading as soon as possible.


OpenCVE Recommended Actions

  • Upgrade IBM Sterling Secure Proxy to version 6.2.1.26.2.1.3 via IBM Fix Central as the official fix
  • Implement a temporary safeguard by configuring the application to strip or escape any user-supplied HTML before rendering it
  • Rotate or revoke credentials that can access the application to reduce the attack window

Generated by OpenCVE AI on September 17, 2026 at 19:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to perform UI spoofing and phishing attacks due to improper neutralization of user-supplied HTML markup.
Title IBM Sterling Secure Proxy is vulnerable to multiple issues
First Time appeared Ibm
Ibm sterling Secure Proxy
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:sterling_secure_proxy:6.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_secure_proxy:6.2.1.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm sterling Secure Proxy
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Ibm Sterling Secure Proxy
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T17:31:47.730Z

Reserved: 2026-08-24T15:05:32.681Z

Link: CVE-2026-78415

cve-icon Vulnrichment

Updated: 2026-09-15T17:26:57.109Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T21:17:25.853

Modified: 2026-09-16T19:24:58.293

Link: CVE-2026-78415

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:00:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')