Sterling External Authentication Server

Vendor:

First CVE: Feb 11, 2020 · Active for 6 years

11
Total CVEs
More Total CVEs than 90% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Sterling External Authentication Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 11, 2020
6 years ago
Most Recent CVE
Sep 5, 2023
1,057 days ago

CVE Severity & Scoring

Sterling External Authentication Server11 CVEs
All CVEs353,173 CVEs
MediumHigh
Attack Vector
Local4 (36.4%)
Network6 (54.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (9.1%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low5 (45.5%)
High1 (9.1%)
None5 (45.5%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Sterling External Authentication Server 6.0.1, 6.0.0, 2.4.3.2, and 2.4.2 and IBM Sterling Secure Proxy 6.0.1, 6.0.0, 3.4.3, and 3.4.2 are vulnerable to an XML External Entity I
Jul 16, 20208.226NONO
IBM Sterling External Authentication Server and IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 could allow a remote user to consume resources causing a denial of service d
Feb 23, 20227.525NONO
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information
Aug 30, 20217.523NONO
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information
Aug 30, 20217.523NONO
IBM Sterling External Authentication Server 6.1.0 and IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptographic algorithms during installation that could allow a loca
Feb 8, 20235.520NONO
A Command Execution Vulnerability exists in IBM Sterling External Authentication Server 2.2.0, 2.3.01, 2.4.0, and 2.4.1 via an unspecified OS command, which could let a local malic
Feb 11, 20207.820NONO
IBM Sterling External Authentication Server 3.4.3.2, 6.0.2.0, and 6.0.3.0 is vulnerable to path traversals, due to not properly validating RESTAPI configuration data. An authorized
Feb 24, 20224.318NONO
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authenticat
Aug 30, 20214.918NONO
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow a local user with specific information about the system to obtain privileged information due to inadequate memory clearing dur
Sep 5, 20235.517NONO
IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be read by a local user with contain
Sep 5, 20235.517NONO

Exploit Exposure

Signals from CVEs in this product scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (11 CVEs).

Media Mentions

Signals from CVEs in this product scope (11 CVEs).

Top CNAs Publishing CVEs For Sterling External Authentication Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.1.035.50.1%00
6.0.3.055.90.8%00
6.0.2.066.41.1%00
6.0.1.047.01.5%00
6.0.0.018.23.3%00
3.4.3.236.11.2%00
2.4.3.247.01.5%00
2.4.2.018.23.3%00
2.4.117.80.6%00
2.4.017.80.6%00
2.3.0117.80.6%00
2.2.017.80.6%00