Vulnerability Bulletins

IBM Security Bulletin: Vulnerability in Castor library affects Sterling Secure Proxy (CVE-2014-3004)

   
Affected software IBM
 
Sterling Secure Proxy is shipped with a third party library called Castor, which is vulnerable to an XML External Entity Injection (XXE) error. The Castor library shipped with Sterling Secure Proxy has been updated to remediate the vulnerability. CVE(s): CVE-2014-3004 Affected product(s) and affected version(s): Sterling Secure Proxy 3.4.2 Sterling Secure Proxy 3.4.1 through 3.4.1.8 iFix05 Sterling Secure Proxy 3.4.0 through 3.4.0.6 iFix05 Sterling Secure Proxy 3.3.1 through 3.3.1.23

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerability_in_castor_library_affects_sterling_secure_proxy_cve_2014_3004?lang=en_us