CVE-2024-39744

IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.3.0:*:*:*:*:*:*:*
OR cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

23 Aug 2024, 15:25

Type Values Removed Values Added
CPE cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.1.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.2.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_connect_direct_web_services:6.0:*:*:*:*:*:*:*
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/297236 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/297236 - VDB Entry, Vendor Advisory
References () https://www.ibm.com/support/pages/node/7166196 - () https://www.ibm.com/support/pages/node/7166196 - Vendor Advisory
Summary
  • (es) IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2 y 6.3 es vulnerable a cross-site request forgery, lo que podría permitir a un atacante ejecutar acciones maliciosas y no autorizadas transmitidas por un usuario en el que confía el sitio web.
First Time Linux
Microsoft
Ibm sterling Connect Direct Web Services
Microsoft windows
Ibm
Linux linux Kernel
Ibm aix

22 Aug 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-22 11:15

Updated : 2024-08-23 15:25


NVD link : CVE-2024-39744

Mitre link : CVE-2024-39744

CVE.ORG link : CVE-2024-39744


JSON object : View

Products Affected

ibm

  • sterling_connect_direct_web_services
  • aix

linux

  • linux_kernel

microsoft

  • windows
CWE
CWE-352

Cross-Site Request Forgery (CSRF)