Impact
IBM Sterling Secure Proxy versions 6.2.0.0 through 6.2.1.2 allow a remote authenticated attacker to conduct UI spoofing and phishing attacks by using improperly neutralized user-supplied HTML markup. The flaw manifests as a stored cross-site scripting vulnerability that injects malicious HTML into the application’s interface, which can appear authentic to users. Attackers can use this injection to trick users into providing credentials or to deliver malware. The vulnerable products are IBM Sterling Secure Proxy in release versions 6.2.0.0 up to 6.2.1.2. All installations within that range are affected, and the fix is incorporated in version 6.2.1.26.2.1.3 and later. The CVSS score of 5.4 indicates moderate risk because an attacker must first authenticate to the system. EPSS is reported as less than 1 %, and the vulnerability is not listed in CISA KEV. Exploitation requires the attacker to log in and then inject malicious HTML, which is rendered in the UI and can lead to credential compromise or malware delivery.
Affected Systems
IBM Sterling Secure Proxy 6.2.0.0 to 6.2.1.2 are vulnerable; the issue is resolved in 6.2.1.26.2.1.3 and later.
Risk and Exploitability
The CVSS score of 5.4 reflects a moderate threat primarily due to the authentication prerequisite. EPSS is below 1 %, and the vulnerability is not captured in the CISA KEV catalog. Attacking paths involve an authorized user injecting HTML that the application renders, enabling phishing and potential credential theft. Although the impact is confined to UI manipulation, the possibility of credential compromise warrants timely remediation.
OpenCVE Enrichment