Identity Spoofing Vulnerability in IBM Sterling Connect:Direct Web Services
CVE-2024-49808

6.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
18 April 2025

Summary

IBM Sterling Connect:Direct Web Services versions 6.1.0, 6.2.0, and 6.3.0 contain a vulnerability that allows authenticated users to impersonate other users due to improper authorization mechanisms. This flaw can be exploited to circumvent access restrictions, potentially exposing sensitive data or operations to unauthorized access. Proper measures should be taken to mitigate this risk, ensuring that authorization checks adequately restrict user actions.

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.