CVE-2024-45653

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 19, 2025
CWE ID 201

Summary

CVE-2024-45653 is a vulnerability affecting IBM Sterling Connect:Direct Web Services versions 6.0, 6.1, 6.2, and 6.3. This issue allows authenticated users to obtain sensitive IP address information from the system's responses. The disclosed IP addresses could potentially be used to launch further attacks against the affected system. IBM strongly recommends users update their software to mitigate this risk. This vulnerability has the potential to impact the security and confidentiality of the affected system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share