Metrics
Affected Vendors & Products
No advisories yet.
Solution
Remediation/Fixes IBM strongly recommends addressing the vulnerability now by upgrading Product Version Remediation/Fix/Instructions IBM Sterling Connect:Direct for UNIX 6.4.0 Apply 6.4.0.2.iFix004, available on Fix Central . IBM Sterling Connect:Direct for UNIX 6.3.0 Apply 6.3.0.5.iFix008, available on Fix Central . IBM Sterling Connect:Direct for UNIX 6.2.0 Apply 6.2.0.9.iFix005, available on Fix Central .
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7249678 |
|
Fri, 12 Dec 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ibm:sterling_connect\:direct:*:*:*:*:*:unix:*:* cpe:2.3:a:ibm:sterling_connect\:direct:6.2.0.9:*:-:*:*:unix:*:* cpe:2.3:a:ibm:sterling_connect\:direct:6.2.0.9:ifix004:-:*:*:unix:*:* cpe:2.3:a:ibm:sterling_connect\:direct:6.3.0.5:*:-:*:*:unix:*:* cpe:2.3:a:ibm:sterling_connect\:direct:6.3.0.5:ifix002:-:*:*:unix:*:* cpe:2.3:a:ibm:sterling_connect\:direct:6.4.0.2:*:-:*:*:unix:*:* cpe:2.3:a:ibm:sterling_connect\:direct:6.4.0.2:ifix001:-:*:*:unix:*:* |
Thu, 30 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Oct 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Sterling Connect Direct for Unix 6.2.0.7 through 6.2.0.9 iFix004, 6.4.0.0 through 6.4.0.2 iFix001, and 6.3.0.2 through 6.3.0.5 iFix002 incorrectly assigns permissions for maintenance tasks to Control Center Director (CCD) users that could allow a privileged user to escalate their privileges further due to unnecessary privilege assignment for post update scripts. | |
| Title | IBM Sterling Connect:Direct for UNIX command execution | |
| First Time appeared |
Ibm
Ibm sterling Connect\ |
|
| Weaknesses | CWE-250 | |
| CPEs | cpe:2.3:a:ibm:sterling_connect\:direct:6.2.0.7:*:*:*:*:unix:*:* cpe:2.3:a:ibm:sterling_connect\:direct:6.2.0.9:ifix004:*:*:*:unix:*:* cpe:2.3:a:ibm:sterling_connect\:direct:6.3.0.2:*:*:*:*:*:*:* cpe:2.3:a:ibm:sterling_connect\:direct:6.3.0.5.:ifix002:*:*:*:unix:*:* cpe:2.3:a:ibm:sterling_connect\:direct:6.4.0.0:*:*:*:*:unix:*:* cpe:2.3:a:ibm:sterling_connect\:direct:6.4.0.2.:ifix001:*:*:*:unix:*:* |
|
| Vendors & Products |
Ibm
Ibm sterling Connect\ |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-11-01T03:55:53.155Z
Reserved: 2025-04-15T21:16:19.008Z
Link: CVE-2025-36137
Updated: 2025-10-30T19:09:06.406Z
Status : Analyzed
Published: 2025-10-30T19:16:23.593
Modified: 2025-12-12T17:25:08.380
Link: CVE-2025-36137
No data.
OpenCVE Enrichment
No data.