← Back

CVE-2025-36137

nvd nist
Published: Oct 30, 2025Modified: Dec 12, 2025

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: psirt@us.ibm.com (Secondary)

Description

IBM Sterling Connect Direct for Unix 6.2.0.7 through 6.2.0.9 iFix004, 6.4.0.0 through 6.4.0.2 iFix001, and 6.3.0.2 through 6.3.0.5 iFix002 incorrectly assigns permissions for maintenance tasks to Control Center Director (CCD) users that could allow a privileged user to escalate their privileges further due to unnecessary privilege assignment for post update scripts.

Affected (9)

1 product
Sterling Connect\
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
From 6.2.0.7 to 6.2.0.9
From 6.3.0.2 to 6.3.0.5
From 6.4.0.0 to 6.4.0.2
Version direct 6.2.0.9
Version direct 6.2.0.9
Version direct 6.3.0.5
Version direct 6.3.0.5
Version direct 6.4.0.2
Version direct 6.4.0.2

References (1)

Source: psirt@us.ibm.com
Vendor Advisory

Timeline

No history available yet.