7.5
CVE-2024-39745
- EPSS 0.08%
- Veröffentlicht 22.08.2024 11:15:13
- Zuletzt bearbeitet 23.08.2024 15:25:13
- Quelle psirt@us.ibm.com
- Teams Watchlist Login
- Unerledigt Login
IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Sterling Connect Direct Web Services Version6.0
Ibm ≫ Sterling Connect Direct Web Services Version6.1.0
Ibm ≫ Sterling Connect Direct Web Services Version6.2.0
Ibm ≫ Sterling Connect Direct Web Services Version6.3.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.08% | 0.234 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
psirt@us.ibm.com | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.