Sceawere

Vulnerability Detail

CVE-2026-78415UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM Sterling Secure Proxy UI Spoofing

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
2h ago
Vendor
IBM
Product
Sterling Secure Proxy
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to perform UI spoofing and phishing attacks due to improper neutralization of user-supplied HTML markup.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-09-14T21:17:25.853Z",
  "pubdate": "2026-09-14T21:17:25.853Z",
  "executiveSummary": "IBM Sterling Secure Proxy versions 6.2.0.0 through 6.2.1.2 are susceptible to a UI spoofing and phishing vulnerability caused by the improper neutralization of user-supplied HTML markup.\nThis vulnerability allows a remote, authenticated attacker to inject arbitrary HTML content into the application interface, enabling the construction of fraudulent pages or deceptive UI elements.\nThe primary risk involves social engineering, where an attacker crafts malicious content to mislead legitimate users into revealing sensitive credentials, performing unauthorized actions, or interacting with malicious external sites.\nSuccessful exploitation requires the attacker to possess authenticated access to the system. While the vulnerability is restricted to authenticated users, it significantly undermines the integrity of the administrative or user portal, posing a risk to organizational security posture and user trust.\nThere are no requirements for specialized network positioning beyond the ability to interact with the application’s web-based interface. The vulnerability resides within the application's input processing logic, which fails to correctly sanitize or encode data rendered back to the user within the browser context.",
  "technicalDetails": "The vulnerability originates from the improper neutralization of user-supplied input before it is rendered within the web interface of IBM Sterling Secure Proxy. The application fails to perform adequate context-aware output encoding or input validation on fields that accept user-defined data. Consequently, an attacker can submit HTML-formatted payloads that the application processes and displays to other users without sufficient filtering.\nThe root cause is a failure in the application's templating or UI rendering engine, which treats user-controlled data as trusted HTML. This allows for the injection of tags, attributes, and scripts that deviate from the intended application structure. By manipulating the Document Object Model (DOM) of the session, the attacker can overlay fraudulent content, modify input forms, or redirect navigation flows.\nThe attack flow begins when an authenticated attacker identifies an input field within the Sterling Secure Proxy management console or user-facing web interface that is reflected back to other users. The attacker crafts a payload containing HTML markup—such as custom <div> or <iframe> elements—designed to mimic legitimate application UI components. Upon submitting this payload, the malicious HTML is stored or reflected by the application. When a victim views the affected page, the browser interprets the injected markup as legitimate application content. This permits the attacker to overlay a fake login prompt, hide legitimate interface elements, or substitute functional buttons with malicious links, effectively facilitating a phishing attack within the trust boundary of the application.\nThis vulnerability is classified as a Cross-Site Scripting (XSS) derivative, specifically focused on UI manipulation. Because the application fails to restrict HTML rendering, the attacker gains the ability to manipulate the visual presentation of the interface for subsequent users. The scope of the impact is broad, as it can be used to harvest session tokens, capture credentials through spoofed forms, or induce users to perform actions they believe are authorized by the system administrator.\nAffected versions include 6.2.0.0 up to and including 6.2.1.2. The exploitation is facilitated by the application's reliance on client-side rendering of server-supplied input without robust sanitization headers or Content Security Policy (CSP) enforcement to mitigate such DOM-based or reflected content injection."
}
CVE-2026-78415: IBM Sterling Secure Proxy UI Spoofing (MEDIUM Severity, CVSS: 5.4) | Sceawere