6.3
CVSSv3

CVE-2024-45651

CVSSv4: NA | CVSSv3: 6.3 | CVSSv2: NA | VMScore: 730 | EPSS: 0.00044 | KEV: Not Included
Published: 18/04/2025 Updated: 21/04/2025

Vulnerability Summary

Session Impersonation Vulnerability in IBM Sterling Connect:Direct Web Services

IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm sterling connect direct web services 6.1.0.0

ibm sterling connect direct web services 6.2.0.0

ibm sterling connect direct web services 6.3.0.0

ibm sterling connect direct web services