CVE-2026-78415

Summary

IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to perform UI spoofing and phishing attacks due to improper neutralization of user-supplied HTML markup.

Affected Software

VendorProductVersion RangeStatus
IBMSterling Secure Proxy6.2.0.0 <= 6.2.1.2affected

Weaknesses

  • CWE-79: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

References