CVE Vulnerabilities

CVE-2025-36137

Execution with Unnecessary Privileges

Published: Oct 30, 2025 | Modified: Dec 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Sterling Connect Direct for Unix 6.2.0.7 through 6.2.0.9 iFix004, 6.4.0.0 through 6.4.0.2 iFix001, and 6.3.0.2 through 6.3.0.5 iFix002 incorrectly assigns permissions for maintenance tasks to Control Center Director (CCD) users that could allow a privileged user to escalate their privileges further due to unnecessary privilege assignment for post update scripts.

Weakness

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

Affected Software

NameVendorStart VersionEnd Version
Sterling_connect:directIbm6.2.0.7 (including)6.2.0.9 (excluding)
Sterling_connect:directIbm6.3.0.2 (including)6.3.0.5 (excluding)
Sterling_connect:directIbm6.4.0.0 (including)6.4.0.2 (excluding)
Sterling_connect:directIbm6.2.0.9 (including)6.2.0.9 (including)
Sterling_connect:directIbm6.2.0.9-ifix004 (including)6.2.0.9-ifix004 (including)
Sterling_connect:directIbm6.3.0.5 (including)6.3.0.5 (including)
Sterling_connect:directIbm6.3.0.5-ifix002 (including)6.3.0.5-ifix002 (including)
Sterling_connect:directIbm6.4.0.2 (including)6.4.0.2 (including)
Sterling_connect:directIbm6.4.0.2-ifix001 (including)6.4.0.2-ifix001 (including)

Potential Mitigations

References