CVE-2024-45651
18.04.2025, 11:15
IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | sterling_connect_direct_web_services | 6.1.0 ≤ 𝑥 < 6.1.0.28 |
ibm | sterling_connect_direct_web_services | 6.2.0 ≤ 𝑥 < 6.2.0.27 |
ibm | sterling_connect_direct_web_services | 6.3.0 ≤ 𝑥 < 6.3.0.13 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration