IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity of another user due to improper authorization which could allow the user to bypass access restrictions.
References
Link | Resource |
---|---|
https://www.ibm.com/support/pages/node/7231180 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
18 Jul 2025, 13:44
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
CPE | cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:* cpe:2.3:a:ibm:sterling_connect_direct_web_services:*:*:*:*:*:*:*:* |
|
References | () https://www.ibm.com/support/pages/node/7231180 - Vendor Advisory | |
First Time |
Linux
Microsoft windows Microsoft Ibm sterling Connect Direct Web Services Linux linux Kernel Ibm Ibm aix |
18 Apr 2025, 11:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-18 11:15
Updated : 2025-07-18 13:44
NVD link : CVE-2024-49808
Mitre link : CVE-2024-49808
JSON object : View
Products Affected
linux
- linux_kernel
ibm
- sterling_connect_direct_web_services
- aix
microsoft
- windows
CWE
CWE-863
Incorrect Authorization