← Back

CVE-2024-49808

nvd nist
Published: Apr 18, 2025Modified: Jul 18, 2025

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity of another user due to improper authorization which could allow the user to bypass access restrictions.

Affected (3)

1 product
Configuration A
3 vulnerable · 3 platform
Vulnerable SoftwareAffected Versions
Ibm
From 6.1.0 to 6.1.0.28
From 6.2.0 to 6.2.0.27
From 6.3.0 to 6.3.0.13
Running on/withPlatform Versions
Ibm
Aix
All versions
Linux
Linux Kernel
All versions
Microsoft
Windows
All versions

References (1)

Source: psirt@us.ibm.com
Vendor Advisory

Timeline

No history available yet.