Unrated severityNVD Advisory· Published Apr 18, 2025· Updated Sep 1, 2025
IBM Sterling Connect:Direct Web Services improper authorization
CVE-2024-49808
Description
IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity of another user due to improper authorization which could allow the user to bypass access restrictions.
Affected products
2cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.1.0.0:*:*:*:*:windows:*:*+ 1 more
- cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.1.0.0:*:*:*:*:windows:*:*range: 6.1.0
- (no CPE)range: 6.1.0, 6.2.0, 6.3.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.ibm.com/support/pages/node/7231180mitrevendor-advisorypatch
News mentions
0No linked articles in our index yet.