Certificate Validation Flaw in IBM Sterling Secure Proxy and Secure External Authentication Server
CVE-2021-29726
5.3MEDIUM
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 17 May 2022
What is CVE-2021-29726?
IBM Sterling Secure Proxy and IBM Secure External Authentication Server versions 6.0.3 exhibit a critical flaw where the system does not adequately validate that a certificate is linked to the corresponding host. This improper certificate validation can potentially allow unauthorized access or mislead the system into trusting invalid certificates, posing a significant security risk. Users are advised to apply patches and monitor their systems to mitigate any possible exploitation.
Affected Version(s)
Secure External Authentication Server 6.0.3
Sterling Secure Proxy 6.0.3