CVE-2024-39745: IBM Sterling Connect:Direct Web Services information disclosure
IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Other sources
IBM Sterling Connect:Direct Web Services uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39745?
CVE-2024-39745 has a high severity due to the use of weaker than expected cryptographic algorithms that can lead to data decryption by attackers.
How do I fix CVE-2024-39745?
To fix CVE-2024-39745, you should apply the latest security patch provided by IBM for Sterling Connect:Direct Web Services.
Which versions of IBM Sterling Connect:Direct Web Services are affected by CVE-2024-39745?
CVE-2024-39745 affects IBM Sterling Connect:Direct Web Services versions 6.0, 6.1, 6.2, and 6.3.
What kind of sensitive information is at risk due to CVE-2024-39745?
CVE-2024-39745 potentially exposes highly sensitive information due to the weaker cryptographic algorithms used.
Is there a known workaround for CVE-2024-39745?
Currently, the recommended approach for CVE-2024-39745 is to update to the latest version of IBM Sterling Connect:Direct Web Services as there are no workarounds provided.