CVE-2024-49808: IBM Sterling Connect:Direct Web Services improper authorization
IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity of another user due to improper authorization which could allow the user to bypass access restrictions.
Other sources
IBM Sterling Connect:Direct Web Services could allow an authenticated user to spoof the identity of another user due to improper authorization which could allow the user to bypass access restrictions.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49808?
CVE-2024-49808 is classified as a critical vulnerability due to its potential for authenticated user identity spoofing.
How do I fix CVE-2024-49808?
To fix CVE-2024-49808, update to the latest version of IBM Sterling Connect:Direct Web Services, preferably version 6.3.0 or later.
What versions of IBM Sterling Connect:Direct Web Services are affected by CVE-2024-49808?
CVE-2024-49808 affects IBM Sterling Connect:Direct Web Services versions 6.1.0, 6.2.0, and 6.3.0.
What type of vulnerability is CVE-2024-49808?
CVE-2024-49808 is an authorization-related vulnerability that allows for user identity spoofing.
Who is impacted by CVE-2024-49808?
Organizations using IBM Sterling Connect:Direct Web Services versions 6.1.0, 6.2.0, or 6.3.0 are impacted by CVE-2024-49808.