IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity of another user due to improper authorization which could allow the user to bypass access restrictions.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.ibm.com/support/pages/node/7231180 |
![]() ![]() |
History
Fri, 18 Apr 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 18 Apr 2025 11:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity of another user due to improper authorization which could allow the user to bypass access restrictions. | |
Title | IBM Sterling Connect:Direct Web Services improper authorization | |
First Time appeared |
Ibm
Ibm sterling Connect Direct Web Services |
|
Weaknesses | CWE-863 | |
CPEs | cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.1.0.0:*:*:*:*:unix:*:* cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.1.0.0:*:*:*:*:windows:*:* cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.2.0.0:*:*:*:*:unix:*:* cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.2.0.0:*:*:*:*:windows:*:* cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.3.0.0:*:*:*:*:unix:*:* cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.3.0.0:*:*:*:*:windows:*:* |
|
Vendors & Products |
Ibm
Ibm sterling Connect Direct Web Services |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ibm
Published: 2025-04-18T11:03:58.511Z
Updated: 2025-04-18T11:59:27.560Z
Reserved: 2024-10-20T13:40:24.085Z
Link: CVE-2024-49808

Updated: 2025-04-18T11:31:59.480Z

Status : Awaiting Analysis
Published: 2025-04-18T11:15:45.920
Modified: 2025-04-21T14:23:45.950
Link: CVE-2024-49808

No data.