The Browser in IBM Sterling Connect:Direct 1.4 before 1.4.0.11 and 1.5 through 1.5.0.1 does not close pages upon the timeout of a session, which allows physically proximate attackers to obtain sensitive administrative-console information by reading the screen of an unattended workstation.
2013-06-21T14:55:01.050
2025-04-11T00:51:21.963
Deferred
CVSSv2: 1.9 (LOW)
AV:L/AC:M/Au:N/C:P/I:N/A:N
3.4
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | sterling_connect_direct_user_interface | 1.4.0.0 | Yes |
Application | ibm | sterling_connect_direct_user_interface | 1.4.0.2 | Yes |
Application | ibm | sterling_connect_direct_user_interface | 1.4.0.3 | Yes |
Application | ibm | sterling_connect_direct_user_interface | 1.4.0.6 | Yes |
Application | ibm | sterling_connect_direct_user_interface | 1.4.0.7 | Yes |
Application | ibm | sterling_connect_direct_user_interface | 1.4.0.10 | Yes |
Application | ibm | sterling_connect_direct_user_interface | 1.5.0.0 | Yes |
Application | ibm | sterling_connect_direct_user_interface | 1.5.0.1 | Yes |