CVE-2024-39747: IBM Sterling Connect Direct Web Services

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses default credentials for potentially critical functionality.

Affected products

  • IBM Sterling Connect Direct Web Services: from 6.0.0.0, before 6.1.0.25 (fixed in 6.1.0.25); from 6.2.0, before 6.2.0.24 (fixed in 6.2.0.24); from 6.3.0, before 6.3.0.9 (fixed in 6.3.0.9)

Published 2024-08-31. Last modified 2026-06-17.