Executive brief
IBM Sterling Secure Proxy is a secure file transfer and message handling gateway used by enterprises to protect data in transit. A vulnerability in versions 6.2.0.0 through 6.2.1.2 allows authenticated attackers to inject malicious HTML markup into the user interface, enabling them to perform UI spoofing and phishing attacks that could trick users into revealing credentials or sensitive information.
Technical details
The vulnerability is a cross-site scripting (XSS) flaw (CWE-79) caused by improper neutralization of user-supplied HTML markup in the web interface. An authenticated remote attacker can inject malicious HTML/JavaScript code that gets rendered in the UI without sanitization. The attack requires prior authentication and network access to the application. An attacker can exploit this to create spoofed login pages, credential theft forms, or redirect users to malicious sites. IBM released a fix in version 6.2.1.3; users should upgrade immediately as no workarounds are available.
Affected products
- IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2
Timeline
- 2026-09-14: disclosed