Identity Spoofing Vulnerability in IBM Sterling Connect:Direct Web Services
CVE-2024-49808
6.3MEDIUM
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 18 April 2025
Summary
IBM Sterling Connect:Direct Web Services versions 6.1.0, 6.2.0, and 6.3.0 contain a vulnerability that allows authenticated users to impersonate other users due to improper authorization mechanisms. This flaw can be exploited to circumvent access restrictions, potentially exposing sensitive data or operations to unauthorized access. Proper measures should be taken to mitigate this risk, ensuring that authorization checks adequately restrict user actions.
References
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published