The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information or modify data by leveraging use of HTTP.
| Software | From | Fixed in |
|---|---|---|
| ibm / sterling_secure_proxy | 3.4.2.0-ifix2 | 3.4.2.0-ifix2.x |
| ibm / sterling_secure_proxy | 3.4.2.0-ifix3 | 3.4.2.0-ifix3.x |
| ibm / sterling_secure_proxy | 3.4.2.0-ifix5 | 3.4.2.0-ifix5.x |
| ibm / sterling_secure_proxy | 3.4.2.0-ifix4 | 3.4.2.0-ifix4.x |
| ibm / sterling_secure_proxy | 3.4.3.0 | 3.4.3.0.x |
| ibm / sterling_secure_proxy | 3.4.2.0-ifix1 | 3.4.2.0-ifix1.x |
| ibm / sterling_secure_proxy | 3.4.2.0 | 3.4.2.0.x |
| ibm / sterling_secure_proxy | 3.4.2.0-ifix7 | 3.4.2.0-ifix7.x |
| ibm / sterling_secure_proxy | 3.4.2.0-ifix6 | 3.4.2.0-ifix6.x |