CVE-2024-39744: IBM Sterling Connect:Direct Web Services cross-site request forgery
IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Other sources
IBM Sterling Connect:Direct Web Services is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39744?
CVE-2024-39744 is classified as a moderate severity vulnerability due to the potential for cross-site request forgery attacks.
How do I fix CVE-2024-39744?
To remediate CVE-2024-39744, update IBM Sterling Connect:Direct Web Services to the latest version available.
Which versions of IBM Sterling Connect:Direct are affected by CVE-2024-39744?
CVE-2024-39744 affects IBM Sterling Connect:Direct Web Services versions 6.0, 6.1, 6.2, and 6.3.
What type of vulnerability is CVE-2024-39744?
CVE-2024-39744 is a cross-site request forgery (CSRF) vulnerability.
Who is the vendor associated with CVE-2024-39744?
The vendor associated with CVE-2024-39744 is IBM.