Ibm Sterling Connect vulnerabilities
22 known vulnerabilities affecting ibm/sterling_connect.
Total CVEs
22
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH8MEDIUM12LOW2
Vulnerabilities
Page 1 of 2
CVE-2025-36137P3HIGHCVSS 7.2≥ 6.2.0.7, < 6.2.0.9≥ 6.3.0.2, < 6.3.0.5+2 more2025-10-30
CVE-2025-36137 [HIGH] CWE-250 CVE-2025-36137: IBM Sterling Connect Direct for Unix 6.2.0.7 through 6.2.0.9 iFix004, 6.4.0.0 through 6.4.0.2 iFix00
IBM Sterling Connect Direct for Unix 6.2.0.7 through 6.2.0.9 iFix004, 6.4.0.0 through 6.4.0.2 iFix001, and 6.3.0.2 through 6.3.0.5 iFix002 incorrectly assigns permissions for maintenance tasks to Control Center Director (CCD) users that could allow a privileged user to escalate their privileges further due to unnecessary privilege assignment for post
nvd
CVE-2021-38890P3HIGHCVSS 7.5≥ 6.0.0, < 6.2.0.12021-11-23
CVE-2021-38890 [HIGH] CWE-307 CVE-2021-38890: IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses an inadequate account lockout setting that
IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 209507.
nvd
CVE-2020-4587P3HIGHCVSS 7.8vdirect2020-08-24
CVE-2020-4587 [HIGH] CWE-787 CVE-2020-4587: IBM Sterling Connect:Direct for UNIX 4.2.0, 4.3.0, 6.0.0, and 6.1.0 is vulnerable to a stack based b
IBM Sterling Connect:Direct for UNIX 4.2.0, 4.3.0, 6.0.0, and 6.1.0 is vulnerable to a stack based buffer ovreflow, caused by improper bounds checking. A local attacker could manipulate CD UNIX to obtain root provileges. IBM X-Force ID: 184578.
nvd
CVE-2021-38933P3HIGHCVSS 7.5fixed in 1.5.0.16092023-07-19
CVE-2021-38933 [HIGH] CWE-327 CVE-2021-38933: IBM Sterling Connect:Direct for UNIX 1.5 uses weaker than expected cryptographic algorithms that cou
IBM Sterling Connect:Direct for UNIX 1.5 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 210574.
nvd
CVE-2021-38891P3HIGHCVSS 7.5≥ 6.0.0, < 6.2.0.12021-11-23
CVE-2021-38891 [HIGH] CWE-326 CVE-2021-38891: IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses weaker than expected cryptographic algorit
IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 209508.
nvd
CVE-2023-32331P3HIGHCVSS 7.5vexpress_for_unix2024-03-04
CVE-2023-32331 [HIGH] CWE-119 CVE-2023-32331: IBM Connect:Express for UNIX 1.5.0 is vulnerable to a buffer overflow that could allow a remote atta
IBM Connect:Express for UNIX 1.5.0 is vulnerable to a buffer overflow that could allow a remote attacker to cause a denial of service through its browser UI. IBM X-Force ID: 254979.
nvd
CVE-2013-4035P3HIGHCVSS 7.3v3.4.0.0v3.4.0.1+3 more2018-05-01
CVE-2013-4035 [HIGH] CWE-310 CVE-2013-4035: IBM Sterling Connect:Direct for OpenVMS 3.4.00, 3.4.01, 3.5.00, 3.6.0, and 3.6.0.1 allow remote atta
IBM Sterling Connect:Direct for OpenVMS 3.4.00, 3.4.01, 3.5.00, 3.6.0, and 3.6.0.1 allow remote attackers to have unspecified impact by leveraging failure to reject client requests for an unencrypted session when used as the server in a TCP/IP session and configured for SSL encryption with the client. IBM X-Force ID: 86138.
nvd
CVE-2025-36065P3MEDIUMCVSS 6.5≥ 5.2.0.00, < 5.2.0.132026-01-20
CVE-2025-36065 [MEDIUM] CWE-613 CVE-2025-36065: IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 doe
IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system.
nvd
CVE-2025-36063P3MEDIUMCVSS 6.5≥ 5.2.0.00, < 5.2.0.132026-01-20
CVE-2025-36063 [MEDIUM] CWE-613 CVE-2025-36063: IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 doe
IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.
nvd
CVE-2020-4767P4HIGHCVSS 7.5≥ 4.7.0.0, < 4.7.0.7≥ 4.8.0.0, < 4.8.0.3+2 more2020-10-28
CVE-2020-4767 [HIGH] CWE-125 CVE-2020-4767: IBM Sterling Connect Direct for Microsoft Windows 4.7, 4.8, 6.0, and 6.1 could allow a remote attack
IBM Sterling Connect Direct for Microsoft Windows 4.7, 4.8, 6.0, and 6.1 could allow a remote attacker to cause a denial of service, caused by a buffer over-read. Bysending a specially crafted request, the attacker could cause the application to crash. IBM X-Force ID: 188906.
nvd
CVE-2025-36115P4MEDIUMCVSS 6.5≥ 5.2.0.00, < 5.2.0.132026-01-20
CVE-2025-36115 [MEDIUM] CWE-384 CVE-2025-36115: IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0.00 through 5.2.0.12 does not
IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0.00 through 5.2.0.12 does not disallow the session id after use which could allow an authenticated user to impersonate another user on the system.
nvd
CVE-2025-36064P4MEDIUMCVSS 5.9≥ 3.1.0.0, < 3.1.0.232025-09-22
CVE-2025-36064 [MEDIUM] CWE-307 CVE-2025-36064: IBM Sterling Connect:Express for Microsoft Windows 3.1.0.0 through 3.1.0.22 uses an inadequate accou
IBM Sterling Connect:Express for Microsoft Windows 3.1.0.0 through 3.1.0.22 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
nvd
CVE-2025-36066P4MEDIUMCVSS 6.1≥ 5.2.0.00, < 5.2.0.132026-01-20
CVE-2025-36066 [MEDIUM] CWE-79 CVE-2025-36066: IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 is
IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2023-29260P4MEDIUMCVSS 5.4vexpress_for_unix2023-07-19
CVE-2023-29260 [MEDIUM] CWE-918 CVE-2023-29260: IBM Sterling Connect:Express for UNIX 1.5 is vulnerable to server-side request forgery (SSRF). This
IBM Sterling Connect:Express for UNIX 1.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 252135.
nvd
CVE-2018-1903P4MEDIUMCVSS 6.7vdirect2019-04-10
CVE-2018-1903 [MEDIUM] CVE-2018-1903: IBM Sterling Connect:Direct for UNIX 4.2.0, 4.3.0, and 6.0.0 could allow a user with restricted sudo
IBM Sterling Connect:Direct for UNIX 4.2.0, 4.3.0, and 6.0.0 could allow a user with restricted sudo access on a system to manipulate CD UNIX to gain full sudo access. IBM X-Force ID: 152532.
nvd
CVE-2025-36113P4MEDIUMCVSS 5.4≥ 5.2.0.00, < 5.2.0.132026-01-20
CVE-2025-36113 [MEDIUM] CWE-79 CVE-2025-36113: IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 is
IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2023-29259P4MEDIUMCVSS 5.3vexpress_for_unix2023-07-19
CVE-2023-29259 [MEDIUM] CVE-2023-29259: IBM Sterling Connect:Express for UNIX 1.5 browser UI is vulnerable to attacks that rely on the use o
IBM Sterling Connect:Express for UNIX 1.5 browser UI is vulnerable to attacks that rely on the use of cookies without the SameSite attribute. IBM X-Force ID: 252055.
nvd
CVE-2012-6352P4MEDIUMCVSS 5.0v4.1.0.0v4.1.0.1+2 more2013-02-02
CVE-2012-6352 [MEDIUM] CWE-119 CVE-2012-6352: The Session Manager in IBM Sterling Connect:Direct through 4.1.0.3 on UNIX allows remote attackers t
The Session Manager in IBM Sterling Connect:Direct through 4.1.0.3 on UNIX allows remote attackers to cause a denial of service (daemon crash and disk consumption) via crafted data.
nvd
CVE-2013-2989P4MEDIUMCVSS 6.8v3.8.00v4.0.00+1 more2013-05-28
CVE-2013-2989 [MEDIUM] CWE-264 CVE-2013-2989: The file-copying functionality in IBM Sterling Connect:Direct 3.8.00, 4.0.00, and 4.1.0 for UNIX on
The file-copying functionality in IBM Sterling Connect:Direct 3.8.00, 4.0.00, and 4.1.0 for UNIX on AIX 6.1 through 7.1 uses incorrect privileges, which allows local users to bypass filesystem read permissions and write permissions by leveraging authentication to the Connect:Direct product.
nvd
CVE-2016-5991P4MEDIUMCVSS 4.5vdirect2016-11-25
CVE-2016-5991 [MEDIUM] CWE-264 CVE-2016-5991: IBM Sterling Connect:Direct 4.5.00, 4.5.01, 4.6.0 before 4.6.0.6 iFix008, and 4.7.0 before 4.7.0.4 o
IBM Sterling Connect:Direct 4.5.00, 4.5.01, 4.6.0 before 4.6.0.6 iFix008, and 4.7.0 before 4.7.0.4 on Windows allows local users to gain privileges via unspecified vectors.
nvd
1 / 2Next →