CVE-2025-36137

Source
https://cve.org/CVERecord?id=CVE-2025-36137
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-36137.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-36137
Published
2025-10-30T19:16:23.593Z
Modified
2026-04-10T05:25:41.619854Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

IBM Sterling Connect Direct for Unix 6.2.0.7 through 6.2.0.9 iFix004, 6.4.0.0 through 6.4.0.2 iFix001, and 6.3.0.2 through 6.3.0.5 iFix002 incorrectly assigns permissions for maintenance tasks to Control Center Director (CCD) users that could allow a privileged user to escalate their privileges further due to unnecessary privilege assignment for post update scripts.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "6.2.0.7"
            },
            {
                "fixed": "6.2.0.9"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "6.3.0.2"
            },
            {
                "fixed": "6.3.0.5"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "6.4.0.0"
            },
            {
                "fixed": "6.4.0.2"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "6.2.0.9"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "6.2.0.9-ifix004"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "6.3.0.5"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "6.3.0.5-ifix002"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "6.4.0.2"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "6.4.0.2-ifix001"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-36137.json"