CVE-2024-45651: IBM Sterling Connect Direct Web Services

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system.

Affected products

  • IBM Sterling Connect Direct Web Services: from 6.1.0, before 6.1.0.28 (fixed in 6.1.0.28); from 6.2.0, before 6.2.0.27 (fixed in 6.2.0.27); from 6.3.0, before 6.3.0.13 (fixed in 6.3.0.13)

Published 2025-04-18. Last modified 2026-06-17.