Certificate Validation Flaw in IBM Sterling Secure Proxy and Secure External Authentication Server
CVE-2021-29726
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 17 May 2022
What is CVE-2021-29726?
IBM Sterling Secure Proxy and IBM Secure External Authentication Server versions 6.0.3 exhibit a critical flaw where the system does not adequately validate that a certificate is linked to the corresponding host. This improper certificate validation can potentially allow unauthorized access or mislead the system into trusting invalid certificates, posing a significant security risk. Users are advised to apply patches and monitor their systems to mitigate any possible exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Secure External Authentication Server 6.0.3
Sterling Secure Proxy 6.0.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved