7.5
CVE-2024-39745
- EPSS 0.08%
- Published 22.08.2024 11:15:13
- Last modified 23.08.2024 15:25:13
- Source psirt@us.ibm.com
- Teams watchlist Login
- Open Login
IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Data is provided by the National Vulnerability Database (NVD)
Ibm ≫ Sterling Connect Direct Web Services Version6.0
Ibm ≫ Sterling Connect Direct Web Services Version6.1.0
Ibm ≫ Sterling Connect Direct Web Services Version6.2.0
Ibm ≫ Sterling Connect Direct Web Services Version6.3.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.08% | 0.234 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
psirt@us.ibm.com | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.