Dromara · Dromara Satoken · CVE-2023-44794
**Name of the Vulnerable Software and Affected Versions**
Dromara SaToken versions 1.36.0 and earlier
IBM Sterling Connect Direct Web Services versions 6.0, 6.1.0, 6.2.0, 6.3.0
IBM Sterling Connect Direct Web Services (Certified Container) versions All
**Description**
An issue allows a remote attacker to escalate privileges via a crafted payload to the URL.
**Recommendations**
For Dromara SaToken versions 1.36.0 and earlier, update to a version later than 1.36.0.
For IBM Sterling Connect Direct Web Services versions 6.0, 6.1.0, 6.2.0, 6.3.0, apply the recommended fix from IBM.
For IBM Sterling Connect Direct Web Services (Certified Container) versions All, apply the recommended fix from IBM.