CVE-2025-14115
8.4IBM · Sterling Connect:Direct for UNIX Container
IBM Sterling Connect:Direct for UNIX contains hard-coded credentials used for inbound authentication, outbound communication, or internal data encryption, posing a significant security risk.
Executive summary
A critical vulnerability involving hard-coded credentials in IBM Sterling Connect:Direct for UNIX allows potential unauthorized access or data decryption.
Vulnerability
The software utilizes hard-coded credentials for authentication and encryption functions, which can be exploited by an attacker with local access to compromise system integrity and confidentiality.
Business impact
The presence of hard-coded credentials represents a severe security flaw that could lead to full system compromise, unauthorized data access, and the potential exposure of sensitive encrypted communications. Given the CVSS score of 8.4, this vulnerability presents a high risk to business operations, as it undermines the fundamental security controls protecting critical data transfer infrastructure.
Remediation
Immediate Action: Upgrade to IBM Sterling Connect:Direct for UNIX Container version 6.3.0.6 Interim Fix 017 or 6.4.0.4 as specified in the IBM security bulletin.
Proactive Monitoring: Review access logs for unusual authentication patterns or unauthorized attempts to access configuration files containing sensitive keys.
Compensating Controls: Restrict local system access to the application container environment to authorized personnel only to limit the ability of an attacker to discover and utilize the hard-coded credentials.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations utilizing IBM Sterling Connect:Direct for UNIX must prioritize the application of the provided security updates to eliminate the hard-coded credentials. This vulnerability is high-severity, and failure to patch leaves the environment susceptible to severe compromise. Please consult the official IBM support documentation referenced in the advisory to ensure the correct fix is applied for your specific version.