CVE-2025-36137

7.2

IBM · Sterling Connect:Direct for Unix

IBM Sterling Connect:Direct for Unix incorrectly assigns permissions for maintenance tasks, allowing privileged users to escalate privileges via post update scripts.

Executive summary

A vulnerability in IBM Sterling Connect:Direct for Unix allows a privileged user to escalate their privileges due to improper permission assignment for maintenance tasks.

Vulnerability

This flaw involves execution with unnecessary privileges (CWE-250), where Control Center Director users are granted excessive permissions during maintenance tasks. The attacker must already possess high privileges to exploit this vulnerability.

Business impact

Successful exploitation of this vulnerability allows an existing privileged user to further escalate their access within the system. Given the CVSS score of 7.2, this represents a significant risk to the integrity and confidentiality of the environment, potentially allowing unauthorized administrative control over the affected server.

Remediation

Immediate Action: Upgrade to the patched versions: 6.4.0.2.iFix004, 6.3.0.5.iFix008, or 6.2.0.9.iFix005, all of which are available via IBM Fix Central.

Proactive Monitoring: Audit system logs for unexpected execution of maintenance or post-update scripts, and monitor for unauthorized privilege escalation attempts by existing administrative users.

Compensating Controls: Restrict access to the Control Center Director interface to only authorized personnel and apply the principle of least privilege to all service accounts associated with the application.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The risk posed by this privilege escalation vulnerability is high, particularly in environments where administrative roles are segmented. Administrators should prioritize the deployment of the provided iFix updates to remediate the underlying permission assignment flaw and prevent unauthorized escalation.

More IBM CVEs

Sources