Session Management Flaw in IBM Sterling Connect:Direct Web Services
CVE-2024-45651
6.3MEDIUM
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 18 April 2025
What is CVE-2024-45651?
A flaw in IBM Sterling Connect:Direct Web Services allows session validation to fail after a browser is closed. This could enable an authenticated user to impersonate another user, posing significant security risks to the system. Users of versions 6.1.0, 6.2.0, and 6.3.0 should be vigilant and apply necessary security measures to mitigate the risks associated with this vulnerability.
Affected Version(s)
Sterling Connect:Direct Web Services 6.1.0
Sterling Connect:Direct Web Services 6.2.0
Sterling Connect:Direct Web Services 6.3.0