Sterling External Authentication Server
Vendor:
First CVE: Feb 11, 2020 · Active for 6 years
11
Total CVEs
More Total CVEs than 90% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Sterling External Authentication Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 11, 2020
6 years ago
Most Recent CVE
Sep 5, 2023
1,057 days ago
CVE Severity & Scoring
Sterling External Authentication Server11 CVEs
55%
45%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local4 (36.4%)
Network6 (54.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (9.1%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low5 (45.5%)
High1 (9.1%)
None5 (45.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-4462HIGH IBM Sterling External Authentication Server 6.0.1, 6.0.0, 2.4.3.2, and 2.4.2 and IBM Sterling Secure Proxy 6.0.1, 6.0.0, 3.4.3, and 3.4.2 are vulnerable to an XML External Entity I | Jul 16, 2020 | 8.2 | 26 | NO | NO |
CVE-2022-22336HIGH IBM Sterling External Authentication Server and IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 could allow a remote user to consume resources causing a denial of service d | Feb 23, 2022 | 7.5 | 25 | NO | NO |
CVE-2021-29723HIGH IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information | Aug 30, 2021 | 7.5 | 23 | NO | NO |
CVE-2021-29722HIGH IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information | Aug 30, 2021 | 7.5 | 23 | NO | NO |
CVE-2022-35720MEDIUM IBM Sterling External Authentication Server 6.1.0 and IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptographic algorithms during installation that could allow a loca | Feb 8, 2023 | 5.5 | 20 | NO | NO |
CVE-2013-0517HIGH A Command Execution Vulnerability exists in IBM Sterling External Authentication Server 2.2.0, 2.3.01, 2.4.0, and 2.4.1 via an unspecified OS command, which could let a local malic | Feb 11, 2020 | 7.8 | 20 | NO | NO |
CVE-2022-22349MEDIUM IBM Sterling External Authentication Server 3.4.3.2, 6.0.2.0, and 6.0.3.0 is vulnerable to path traversals, due to not properly validating RESTAPI configuration data. An authorized | Feb 24, 2022 | 4.3 | 18 | NO | NO |
CVE-2021-29728MEDIUM IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authenticat | Aug 30, 2021 | 4.9 | 18 | NO | NO |
CVE-2023-29261MEDIUM IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow a local user with specific information about the system to obtain privileged information due to inadequate memory clearing dur | Sep 5, 2023 | 5.5 | 17 | NO | NO |
CVE-2023-32338MEDIUM IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be read by a local user with contain | Sep 5, 2023 | 5.5 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Sterling External Authentication Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.1.0 | 3 | 5.5 | 0.1% | 0 | 0 |
| 6.0.3.0 | 5 | 5.9 | 0.8% | 0 | 0 |
| 6.0.2.0 | 6 | 6.4 | 1.1% | 0 | 0 |
| 6.0.1.0 | 4 | 7.0 | 1.5% | 0 | 0 |
| 6.0.0.0 | 1 | 8.2 | 3.3% | 0 | 0 |
| 3.4.3.2 | 3 | 6.1 | 1.2% | 0 | 0 |
| 2.4.3.2 | 4 | 7.0 | 1.5% | 0 | 0 |
| 2.4.2.0 | 1 | 8.2 | 3.3% | 0 | 0 |
| 2.4.1 | 1 | 7.8 | 0.6% | 0 | 0 |
| 2.4.0 | 1 | 7.8 | 0.6% | 0 | 0 |
| 2.3.01 | 1 | 7.8 | 0.6% | 0 | 0 |
| 2.2.0 | 1 | 7.8 | 0.6% | 0 | 0 |