6.3
CVSSv3

CVE-2024-49808

CVSSv4: NA | CVSSv3: 6.3 | CVSSv2: NA | VMScore: 730 | EPSS: 0.00044 | KEV: Not Included
Published: 18/04/2025 Updated: 21/04/2025

Vulnerability Summary

Identity Spoofing Vulnerability in IBM Sterling Connect:Direct Web Services

IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity of another user due to improper authorization which could allow the user to bypass access restrictions.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm sterling connect direct web services 6.1.0.0

ibm sterling connect direct web services 6.2.0.0

ibm sterling connect direct web services 6.3.0.0

ibm sterling connect direct web services