Sterling Secure Proxy

Vendor:

First CVE: May 10, 2013 · Active for 13 years

31
Total CVEs
More Total CVEs than 97% of tracked products
3.9
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Sterling Secure Proxy over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 10, 2013
13 years ago
Most Recent CVE
May 28, 2025
426 days ago

CVE Severity & Scoring

Sterling Secure Proxy31 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local4 (12.9%)
Network22 (71.0%)
Unknown3 (9.7%)
Physical0 (0.0%)
Adjacent Network2 (6.5%)
Attack Complexity
Low27 (87.1%)
High1 (3.2%)
Unknown3 (9.7%)
User Interaction
None22 (71.0%)
Unknown3 (9.7%)
Required6 (19.4%)
Privileges Required
Low6 (19.4%)
High2 (6.5%)
None20 (64.5%)
Unknown3 (9.7%)

Top CVEs

Signals from CVEs in this product scope (31 CVEs).

31 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inject commands into the underlying operating system due to impr
Jan 19, 20259.127NONO
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker to retrieve or alter sensitive information contents due to i
Jan 19, 20259.127NONO
IBM Sterling External Authentication Server 6.0.1, 6.0.0, 2.4.3.2, and 2.4.2 and IBM Sterling Secure Proxy 6.0.1, 6.0.0, 3.4.3, and 3.4.2 are vulnerable to an XML External Entity I
Jul 16, 20208.226NONO
IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 230522.
Dec 6, 20227.525NONO
IBM Sterling External Authentication Server and IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 could allow a remote user to consume resources causing a denial of service d
Feb 23, 20227.525NONO
Directory traversal vulnerability in the Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows remote attacker
Oct 6, 20167.525NONO
IBM Secure External Authentication Server 2.4.3.2, 6.0.1, 6.0.2 and IBM Secure Proxy 3.4.3.2, 6.0.1, 6.0.2 could allow a remote user to consume resources causing a denial of servic
Jul 15, 20217.524NONO
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information
Aug 30, 20217.523NONO
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information
Aug 30, 20217.523NONO
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, and 6.1.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially cr
Nov 15, 20247.521NONO

Exploit Exposure

Signals from CVEs in this product scope (31 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (31 CVEs).

Media Mentions

Signals from CVEs in this product scope (31 CVEs).

Top CNAs Publishing CVEs For Sterling Secure Proxy

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.2.0.029.10.6%00
6.1.0.029.10.6%00
6.1.085.40.3%00
6.0.3.037.21.1%00
6.0.3115.30.4%00
6.0.2.017.50.6%00
6.0.276.71.3%00
6.0.1.027.81.9%00
6.0.146.81.4%00
6.0.0.027.81.9%00
3.4.3.266.91.4%00
3.4.3.056.61.4%00
3.4.2.056.31.0%00
3.4.1.634.41.1%00
3.4.1.534.41.1%00
3.4.1.234.41.1%00
3.4.1.034.41.1%00
3.4.0.034.41.1%00
3.3.0.134.41.1%00
3.2.0.034.41.1%00