Man-in-the-Middle Vulnerability in IBM Sterling Secure Proxy
CVE-2016-6026
5.3MEDIUM
What is CVE-2016-6026?
The Configuration Manager in IBM Sterling Secure Proxy (SSP) versions 3.4.2 prior to iFix 8 and 3.4.3 prior to iFix 1 is vulnerable to man-in-the-middle attacks. This issue arises from the acceptance of HTTP methods that are neither GET nor POST, which allows unauthorized attackers to intercept sensitive data transmitted between users and the server. Organizations using affected versions should take immediate steps to mitigate this vulnerability by updating to the recommended patches.