IBM Sterling Connect:Direct Web Services
cpe:2.3:a:ibm:sterling_connect_direct_web_services:*:*:*:*:*:*:*
- 6.1.0
- 6.2.0
- 6.3.0
A session management vulnerability has been identified in IBM Sterling Connect:Direct Web Services versions 6.1.0, 6.2.0, and 6.3.0. The vulnerability arises because the application does not invalidate user sessions after a browser is closed. This oversight could enable an authenticated user to impersonate another user on the system.
Exploitation of this vulnerability could lead to unauthorized user impersonation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.