CVE-2024-45653

IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could disclose sensitive IP address information to authenticated users in responses that could be used in further attacks against the system.
References
Link Resource
https://www.ibm.com/support/pages/node/7174104 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.3.0:*:*:*:*:*:*:*

History

25 Mar 2025, 14:27

Type Values Removed Values Added
First Time Ibm sterling Connect Direct Web Services
Ibm
CPE cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.0.0:*:*:*:*:*:*:*
References () https://www.ibm.com/support/pages/node/7174104 - () https://www.ibm.com/support/pages/node/7174104 - Vendor Advisory
Summary
  • (es) IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2 y 6.3 podrían revelar información confidencial de direcciones IP a usuarios autenticados en respuestas que podrían usarse en futuros ataques contra sistema.
CWE NVD-CWE-noinfo

19 Jan 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-19 03:15

Updated : 2025-03-25 14:27


NVD link : CVE-2024-45653

Mitre link : CVE-2024-45653

CVE.ORG link : CVE-2024-45653


JSON object : View

Products Affected

ibm

  • sterling_connect_direct_web_services
CWE
CWE-201

Insertion of Sensitive Information Into Sent Data

NVD-CWE-noinfo