CVE-2024-45651: IBM Sterling Connect:Direct Web Services session fixation
IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0
does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system.
Other sources
IBM Sterling Connect:Direct Web Services does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45651?
CVE-2024-45651 is considered a critical vulnerability due to its potential exploitation, allowing session hijacking.
How do I fix CVE-2024-45651?
To fix CVE-2024-45651, it is recommended to apply the latest patches provided by IBM for Sterling Connect:Direct Web Services.
What versions are affected by CVE-2024-45651?
CVE-2024-45651 affects IBM Sterling Connect:Direct Web Services versions 6.1.0 through 6.3.0.
What is the impact of CVE-2024-45651?
The impact of CVE-2024-45651 allows authenticated users to remain logged in after closing their browser, increasing the risk of unauthorized impersonation.
Is there a workaround for CVE-2024-45651?
Currently, there are no recommended workarounds for CVE-2024-45651, and updating to the patched version is the best course of action.