Vulnerability Description
IBM Sterling Connect Direct for Unix 6.2.0.7 through 6.2.0.9 iFix004, 6.4.0.0 through 6.4.0.2 iFix001, and 6.3.0.2 through 6.3.0.5 iFix002 incorrectly assigns permissions for maintenance tasks to Control Center Director (CCD) users that could allow a privileged user to escalate their privileges further due to unnecessary privilege assignment for post update scripts.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Sterling Connect\ | >= 6.2.0.7, < 6.2.0.9, direct |
Related Weaknesses (CWE)
References
- https://www.ibm.com/support/pages/node/7249678Vendor Advisory
FAQ
What is CVE-2025-36137?
CVE-2025-36137 is a vulnerability with a CVSS score of 7.2 (HIGH). IBM Sterling Connect Direct for Unix 6.2.0.7 through 6.2.0.9 iFix004, 6.4.0.0 through 6.4.0.2 iFix001, and 6.3.0.2 through 6.3.0.5 iFix002 incorrectly assigns permissions for maintenance tasks to Cont...
How severe is CVE-2025-36137?
CVE-2025-36137 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-36137?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Sterling Connect\.