IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity of another user due to improper authorization which could allow the user to bypass access restrictions.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.ibm.com/support/pages/node/7231180 |
![]() ![]() |
History
Fri, 18 Apr 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 18 Apr 2025 11:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity of another user due to improper authorization which could allow the user to bypass access restrictions. | |
Title | IBM Sterling Connect:Direct Web Services improper authorization | |
First Time appeared |
Ibm
Ibm sterling Connect Direct Web Services |
|
Weaknesses | CWE-863 | |
CPEs | cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.1.0.0:*:*:*:*:unix:*:* cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.1.0.0:*:*:*:*:windows:*:* cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.2.0.0:*:*:*:*:unix:*:* cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.2.0.0:*:*:*:*:windows:*:* cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.3.0.0:*:*:*:*:unix:*:* cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.3.0.0:*:*:*:*:windows:*:* |
|
Vendors & Products |
Ibm
Ibm sterling Connect Direct Web Services |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-04-18T11:59:27.560Z
Reserved: 2024-10-20T13:40:24.085Z
Link: CVE-2024-49808

Updated: 2025-04-18T11:31:59.480Z

Status : Received
Published: 2025-04-18T11:15:45.920
Modified: 2025-04-18T11:15:45.920
Link: CVE-2024-49808

No data.