CVE-2024-49808
CVSS 3.1 Score 6.3 of 10 (medium)
Details
Published Apr 18, 2025
Updated: Apr 21, 2025
CWE ID 863
Summary
CVE-2024-49808 is a vulnerability affecting IBM Sterling Connect:Direct Web Services versions 6.1.0, 6.2.0, and 6.3.0. An authenticated user can exploit this issue to spoof another user's identity, bypassing access restrictions. The improper authorization in the software allows the user to assume another user's identity, potentially leading to unauthorized access to sensitive information or unintended actions. IBM strongly recommends upgrading to a patched version of the software to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- IBM