CVE-2016-0380: IBM Sterling Connect:direct

Low severity, CVSS 3.3. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM Sterling Connect:Direct for Unix 4.1.0 before 4.1.0.4 iFix073 and 4.2.0 before 4.2.0.4 iFix003 uses default file permissions of 0664, which allows local users to obtain sensitive information via standard filesystem operations.

Affected products

  • IBM Sterling Connect:direct: version 4.1.0.0 only; version 4.1.0.1 only; version 4.1.0.2 only; version 4.1.0.3 only; version 4.1.0.4 only; version 4.2.0.0 only; …

Published 2016-08-08. Last modified 2026-06-17.