← back
CVE-2024-39747highCWE-1392

IBM Sterling Connect:Direct Web Services information disclosure

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.1epss 0.8%
exploitation probability
0.8%top 48% of all CVEs
observed exploitation
nono source reports it
In short

IBM Sterling Connect:Direct Web Services comes with default login credentials that attackers can use to access critical functions without authorization. This allows unauthorized access to potentially sensitive operations and data.

Technical detail

The vulnerability stems from hardcoded default credentials in IBM Sterling Connect:Direct Web Services versions 6.0-6.3, enabling unauthenticated or default-authenticated access to critical web service functions. An attacker can exploit this with minimal preconditions (network access to the web service) to gain unauthorized access to sensitive operations and information disclosure.

Summary generated and translated by AI from the official description.
IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses default credentials for potentially critical functionality.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H