IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
2024-08-22T11:15:13.513
2024-08-23T15:25:31.390
Analyzed
CVSSv3.1: 4.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | sterling_connect_direct_web_services | 6.0 | Yes |
Application | ibm | sterling_connect_direct_web_services | 6.1.0 | Yes |
Application | ibm | sterling_connect_direct_web_services | 6.2.0 | Yes |
Application | ibm | sterling_connect_direct_web_services | 6.3.0 | Yes |
Operating System | ibm | aix | - | No |
Operating System | linux | linux_kernel | - | No |
Operating System | microsoft | windows | - | No |