CVE-2024-41784

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Nov 15, 2024
CWE ID 32

Summary

CVE-2024-41784 is a vulnerability affecting IBM Sterling Secure Proxy versions 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, and 6.1.0.0. An attacker can exploit this issue by sending a maliciously crafted URL request containing "dot dot dot" sequences (/.../) to traverse directories on the system. Successful exploitation may grant the attacker unauthorized access to arbitrary files, potentially leading to sensitive data exposure or system compromise. IBM strongly advises users to update their software to a patched version as soon as possible to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • IBM Sterling Secure Proxy

Affected Vendors

  • IBM Corporation