Security Advisory
CVE-2016-6027
6.1
MEDIUM
Vulnerability Description
The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information or modify data by leveraging use of HTTP.
Published Date
October 6, 2016
Official Source
NIST NVD Advisory