CVE 7.2 HIGH

IBM Sterling Connect:Direct for UNIX command execution_CVE-2025-36137

7.2 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Description

IBM Sterling Connect Direct for Unix 6.2.0.7 through 6.2.0.9 iFix004, 6.4.0.0 through 6.4.0.2 iFix001, and 6.3.0.2 through 6.3.0.5 iFix002 incorrectly assigns permissions for maintenance tasks to Control Center Director (CCD) users that could allow a privileged user to escalate their privileges further due to unnecessary privilege assignment for post update scripts.

Basic Information

ID CVE-2025-36137
Source ibm
Published Oct 30, 2025 at 18:53
Modified Oct 30, 2025 at 19:09

Affected Product

Vendor IBM
Product Sterling Connect:Direct for Unix
Version 6.2.0.7
Affected Versions IBM Sterling Connect:Direct for Unix 6.2.0.7
IBM Sterling Connect:Direct for Unix 6.4.0.0
IBM Sterling Connect:Direct for Unix 6.3.0.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.