CVE-2021-29726Improper Certificate Validation in IBM Secure External Authentication Server

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 78.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 17
Latest updateMay 18

Description

IBM Sterling Secure Proxy 6.0.3 and IBM Secure External Authentication Server 6.0.3 does not properly ensure that a certificate is actually associated with the host due to improper validation of certificates. IBM X-Force ID: 201104.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-r9vh-gjqp-fh37: IBM Sterling Secure Proxy 62022-05-18
CVEList
CVE-2021-29726: IBM Sterling Secure Proxy 62022-05-17
CVE-2021-29726 — Improper Certificate Validation in IBM | cvebase