PT-2025-17293 · Ibm · Ibm Sterling Connect:Direct Web Services

Published

2025-04-18

·

Updated

2025-04-18

·

CVE-2024-49808

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions IBM Sterling Connect:Direct Web Services versions 6.1.0 through 6.3.0
Description The issue allows an authenticated user to spoof the identity of another user due to improper authorization, which could enable the user to bypass access restrictions.
Recommendations For versions 6.1.0 through 6.3.0, update to a version that properly enforces authorization to prevent user identity spoofing. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-49808

Affected Products

Ibm Sterling Connect:Direct Web Services