CVE-2024-45651

Publication date

2025-04-18 11:04:55

Family

ibm

State

PUBLISHED

Description

IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system.