IBM Sterling Connect Direct for Unix 6.2.0.7 through 6.2.0.9 iFix004, 6.4.0.0 through 6.4.0.2 iFix001, and 6.3.0.2 through 6.3.0.5 iFix002 incorrectly assigns permissions for maintenance tasks to Control Center Director (CCD) users that could allow a privileged user to escalate their privileges further due to unnecessary privilege assignment for post update scripts.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7249678 |
|
History
Fri, 12 Dec 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ibm:sterling_connect\:direct:*:*:*:*:*:unix:*:* cpe:2.3:a:ibm:sterling_connect\:direct:6.2.0.9:*:-:*:*:unix:*:* cpe:2.3:a:ibm:sterling_connect\:direct:6.2.0.9:ifix004:-:*:*:unix:*:* cpe:2.3:a:ibm:sterling_connect\:direct:6.3.0.5:*:-:*:*:unix:*:* cpe:2.3:a:ibm:sterling_connect\:direct:6.3.0.5:ifix002:-:*:*:unix:*:* cpe:2.3:a:ibm:sterling_connect\:direct:6.4.0.2:*:-:*:*:unix:*:* cpe:2.3:a:ibm:sterling_connect\:direct:6.4.0.2:ifix001:-:*:*:unix:*:* |
Thu, 30 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Oct 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Sterling Connect Direct for Unix 6.2.0.7 through 6.2.0.9 iFix004, 6.4.0.0 through 6.4.0.2 iFix001, and 6.3.0.2 through 6.3.0.5 iFix002 incorrectly assigns permissions for maintenance tasks to Control Center Director (CCD) users that could allow a privileged user to escalate their privileges further due to unnecessary privilege assignment for post update scripts. | |
| Title | IBM Sterling Connect:Direct for UNIX command execution | |
| First Time appeared |
Ibm
Ibm sterling Connect\ |
|
| Weaknesses | CWE-250 | |
| CPEs | cpe:2.3:a:ibm:sterling_connect\:direct:6.2.0.7:*:*:*:*:unix:*:* cpe:2.3:a:ibm:sterling_connect\:direct:6.2.0.9:ifix004:*:*:*:unix:*:* cpe:2.3:a:ibm:sterling_connect\:direct:6.3.0.2:*:*:*:*:*:*:* cpe:2.3:a:ibm:sterling_connect\:direct:6.3.0.5.:ifix002:*:*:*:unix:*:* cpe:2.3:a:ibm:sterling_connect\:direct:6.4.0.0:*:*:*:*:unix:*:* cpe:2.3:a:ibm:sterling_connect\:direct:6.4.0.2.:ifix001:*:*:*:unix:*:* |
|
| Vendors & Products |
Ibm
Ibm sterling Connect\ |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-11-01T03:55:53.155Z
Reserved: 2025-04-15T21:16:19.008Z
Link: CVE-2025-36137
Updated: 2025-10-30T19:09:06.406Z
Status : Analyzed
Published: 2025-10-30T19:16:23.593
Modified: 2025-12-12T17:25:08.380
Link: CVE-2025-36137
No data.