CVE-2021-29722

Severity
7.5HIGH
EPSS
0.1%
top 65.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 30
Latest updateMay 24

Description

IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 201095.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

CVEListV5ibm/sterling_secure_proxy4 versions+3
NVDibm/sterling_secure_proxy3.4.3.2, 6.0.1, 6.0.2+2
NVDibm/sterling_external_authentication_server2.4.3.2, 6.0.1.0, 6.0.2.0+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gqc5-fq98-6v4q: IBM Sterling Secure Proxy 62022-05-24
CVEList
CVE-2021-29722: IBM Sterling Secure Proxy 62021-08-30
CVE-2021-29722 (HIGH CVSS 7.5) | IBM Sterling Secure Proxy 6.0.1 | cvebase.io