CVE-2025-36137: IBM Sterling Connect:direct
High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.
IBM Sterling Connect Direct for Unix 6.2.0.7 through 6.2.0.9 iFix004, 6.4.0.0 through 6.4.0.2 iFix001, and 6.3.0.2 through 6.3.0.5 iFix002 incorrectly assigns permissions for maintenance tasks to Control Center Director (CCD) users that could allow a privileged user to escalate their privileges further due to unnecessary privilege assignment for post update scripts.
Affected products
- IBM Sterling Connect:direct: from 6.2.0.7, before 6.2.0.9 (fixed in 6.2.0.9); from 6.3.0.2, before 6.3.0.5 (fixed in 6.3.0.5); from 6.4.0.0, before 6.4.0.2 (fixed in 6.4.0.2); version 6.2.0.9 only; version 6.3.0.5 only; version 6.4.0.2 only
Published 2025-10-30. Last modified 2026-10-07.