Identity Spoofing Vulnerability in IBM Sterling Connect:Direct Web Services
CVE-2024-49808
6.3MEDIUM
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 18 April 2025
What is CVE-2024-49808?
IBM Sterling Connect:Direct Web Services versions 6.1.0, 6.2.0, and 6.3.0 contain a vulnerability that allows authenticated users to impersonate other users due to improper authorization mechanisms. This flaw can be exploited to circumvent access restrictions, potentially exposing sensitive data or operations to unauthorized access. Proper measures should be taken to mitigate this risk, ensuring that authorization checks adequately restrict user actions.
Affected Version(s)
Sterling Connect:Direct Web Services 6.1.0
Sterling Connect:Direct Web Services 6.2.0
Sterling Connect:Direct Web Services 6.3.0