7.2
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Description
IBM Sterling Connect Direct for Unix 6.2.0.7 through 6.2.0.9 iFix004, 6.4.0.0 through 6.4.0.2 iFix001, and 6.3.0.2 through 6.3.0.5 iFix002 incorrectly assigns permissions for maintenance tasks to Control Center Director (CCD) users that could allow a privileged user to escalate their privileges further due to unnecessary privilege assignment for post update scripts.
Basic Information
ID
CVE-2025-36137
Source
ibm
Published
Oct 30, 2025 at 18:53
Modified
Oct 30, 2025 at 19:09
Affected Product
Vendor
IBM
Product
Sterling Connect:Direct for Unix
Version
6.2.0.7
Affected Versions
IBM Sterling Connect:Direct for Unix 6.2.0.7
IBM Sterling Connect:Direct for Unix 6.4.0.0
IBM Sterling Connect:Direct for Unix 6.3.0.2
IBM Sterling Connect:Direct for Unix 6.4.0.0
IBM Sterling Connect:Direct for Unix 6.3.0.2