CVE-2024-38337

Published Jan 19, 2025

Last updated a month ago

Overview

Description
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker to retrieve or alter sensitive information contents due to incorrect permission assignments.
Source
psirt@us.ibm.com
NVD status
Received

Risk scores

CVSS 3.1

Type
Primary
Base score
9.1
Impact score
5.2
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity
CRITICAL

Weaknesses

psirt@us.ibm.com
CWE-732

Social media

Hype score
Not currently trending
  1. Warning: Critical vulnerabilities in @IBM Sterling Secure Proxy. CVE-2024-41783 & CVE-2024-38337, CVSS 9.1. They allow an unauthorized attacker to alter/retrieve data or a privileged attacker to inject commands to the underlying operating system. #Patch https://t.co/iqDPN6Yvq

    @CCBalert

    21 Jan 2025

    179 Impressions

    1 Retweet

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  2. IBM Sterling Secure Proxy Faces Multiple Critical Vulnerabilities: A Call for Immediate Action Discover the critical flaws affecting IBM Sterling Secure Proxy. Learn about CVE-2024-41783 and CVE-2024-38337 and their potential impact on data security https://t.co/SRg8U6hC1t

    @the_yellow_fall

    21 Jan 2025

    477 Impressions

    3 Retweets

    15 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2024-38337 Unauthorized Access to Sensitive Data in IBM Sterling Secure Proxy https://t.co/k6a3CIYbwC

    @VulmonFeeds

    19 Jan 2025

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. New post from https://t.co/uXvPWJy6tj (CVE-2024-38337 | IBM Sterling Secure Proxy up to 6.2.0.0 permission assignment) has been published on https://t.co/z5ROMzeKm8

    @WolfgangSesin

    19 Jan 2025

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. [CVE-2024-38337: CRITICAL] IBM Sterling Secure Proxy versions 6.0.0.0 to 6.2.0.0 may expose sensitive data to unauthorized access or modification due to incorrect permission settings. #cybersecurity#cybersecurity,#vulnerability https://t.co/ue0zEY5MQJ https://t.co/HjNuDgBipy

    @CveFindCom

    19 Jan 2025

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes