← Back

CVE-2024-39746

nvd nist
Published: Aug 22, 2024Modified: Sep 29, 2025

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

Affected (4)

1 product
Configuration A
4 vulnerable · 3 platform
Vulnerable SoftwareAffected Versions
Ibm
Version 6.0
Version 6.1.0
Version 6.2.0
Version 6.3.0
Running on/withPlatform Versions
Ibm
Aix
All versions
Linux
Linux Kernel
All versions
Microsoft
Windows
All versions

References (1)

Source: psirt@us.ibm.com
Vendor Advisory

Timeline

No history available yet.