CVE-2024-45651: IBM Sterling Connect Direct Web Services
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system.
Affected products
- IBM Sterling Connect Direct Web Services: from 6.1.0, before 6.1.0.28 (fixed in 6.1.0.28); from 6.2.0, before 6.2.0.27 (fixed in 6.2.0.27); from 6.3.0, before 6.3.0.13 (fixed in 6.3.0.13)
Published 2025-04-18. Last modified 2026-06-17.