CVE Vulnerabilities

CVE-2024-39747

Use of Default Credentials

Published: Aug 31, 2024 | Modified: Sep 16, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses default credentials for potentially critical functionality.

Weakness

The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.

Affected Software

Name Vendor Start Version End Version
Sterling_connect_direct_web_services Ibm 6.0.0.0 (including) 6.1.0.25 (excluding)
Sterling_connect_direct_web_services Ibm 6.2.0 (including) 6.2.0.24 (excluding)
Sterling_connect_direct_web_services Ibm 6.3.0 (including) 6.3.0.9 (excluding)

Potential Mitigations

References