IBM Sterling Secure Proxy Command Injection Vulnerability in Privileged User Context

Vulnerability

A command injection vulnerability has been identified in IBM Sterling Secure Proxy versions 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0. This vulnerability could allow a privileged user to inject commands into the underlying operating system, arising from improper validation of certain input types.

Impact

Exploitation of this vulnerability could lead to unauthorized command execution on the underlying operating system with the privileges of the user running the IBM Sterling Secure Proxy application.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
2.5
exploitability
5.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.