VYPR

Sterling Connect\

by IBM

CVEs (24)

  • CVE-2020-4587HigAug 24, 2020
    risk 0.51cvss 7.8epss 0.00

    IBM Sterling Connect:Direct for UNIX 4.2.0, 4.3.0, 6.0.0, and 6.1.0 is vulnerable to a stack based buffer ovreflow, caused by improper bounds checking. A local attacker could manipulate CD UNIX to obtain root provileges. IBM X-Force ID: 184578.

  • CVE-2023-32331HigMar 4, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Connect:Express for UNIX 1.5.0 is vulnerable to a buffer overflow that could allow a remote attacker to cause a denial of service through its browser UI. IBM X-Force ID: 254979.

  • CVE-2021-38891HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 209508.

  • CVE-2021-38890HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.02

    IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 209507.

  • CVE-2020-4767HigOct 28, 2020
    risk 0.49cvss 7.5epss 0.02

    IBM Sterling Connect Direct for Microsoft Windows 4.7, 4.8, 6.0, and 6.1 could allow a remote attacker to cause a denial of service, caused by a buffer over-read. Bysending a specially crafted request, the attacker could cause the application to crash. IBM X-Force ID: 188906.

  • CVE-2025-36137HigOct 30, 2025
    risk 0.47cvss 7.2epss 0.00

    IBM Sterling Connect Direct for Unix 6.2.0.7 through 6.2.0.9 iFix004, 6.4.0.0 through 6.4.0.2 iFix001, and 6.3.0.2 through 6.3.0.5 iFix002 incorrectly assigns permissions for maintenance tasks to Control Center Director (CCD) users that could allow a privileged user to escalate…

  • CVE-2013-4035HigMay 1, 2018
    risk 0.47cvss 7.3epss 0.00

    IBM Sterling Connect:Direct for OpenVMS 3.4.00, 3.4.01, 3.5.00, 3.6.0, and 3.6.0.1 allow remote attackers to have unspecified impact by leveraging failure to reject client requests for an unencrypted session when used as the server in a TCP/IP session and configured for SSL…

  • CVE-2018-1903MedApr 10, 2019
    risk 0.44cvss 6.7epss 0.00

    IBM Sterling Connect:Direct for UNIX 4.2.0, 4.3.0, and 6.0.0 could allow a user with restricted sudo access on a system to manipulate CD UNIX to gain full sudo access. IBM X-Force ID: 152532.

  • CVE-2023-29260MedJul 19, 2023
    risk 0.42cvss 6.5epss 0.00

    IBM Sterling Connect:Express for UNIX 1.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: …

  • CVE-2025-36115MedJan 20, 2026
    risk 0.41cvss 6.3epss 0.00

    IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0.00 through 5.2.0.12 does not disallow the session id after use which could allow an authenticated user to impersonate another user on the system.

  • CVE-2025-36065MedJan 20, 2026
    risk 0.41cvss 6.3epss 0.00

    IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system.

  • CVE-2025-36063MedJan 20, 2026
    risk 0.41cvss 6.3epss 0.00

    IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.

  • CVE-2025-36066MedJan 20, 2026
    risk 0.40cvss 6.1epss 0.00

    IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality…

  • CVE-2025-36064MedSep 22, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Sterling Connect:Express for Microsoft Windows 3.1.0.0 through 3.1.0.22 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

  • CVE-2021-38933MedJul 19, 2023
    risk 0.38cvss 5.9epss 0.00

    IBM Sterling Connect:Direct for UNIX 1.5 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 210574.

  • CVE-2025-36113MedJan 20, 2026
    risk 0.35cvss 5.4epss 0.00

    IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality…

  • CVE-2016-5991MedNov 25, 2016
    risk 0.29cvss 4.5epss 0.00

    IBM Sterling Connect:Direct 4.5.00, 4.5.01, 4.6.0 before 4.6.0.6 iFix008, and 4.7.0 before 4.7.0.4 on Windows allows local users to gain privileges via unspecified vectors.

  • CVE-2023-29259LowJul 19, 2023
    risk 0.24cvss 3.7epss 0.00

    IBM Sterling Connect:Express for UNIX 1.5 browser UI is vulnerable to attacks that rely on the use of cookies without the SameSite attribute. IBM X-Force ID: 252055.

  • CVE-2016-0380LowAug 8, 2016
    risk 0.21cvss 3.3epss 0.00

    IBM Sterling Connect:Direct for Unix 4.1.0 before 4.1.0.4 iFix073 and 4.2.0 before 4.2.0.4 iFix003 uses default file permissions of 0664, which allows local users to obtain sensitive information via standard filesystem operations.

  • CVE-2016-5992LowNov 25, 2016
    risk 0.16cvss 2.5epss 0.00

    IBM Sterling Connect:Direct 4.5.00, 4.5.01, 4.6.0 before 4.6.0.6 iFix008, and 4.7.0 before 4.7.0.4 on Windows allows local users to cause a denial of service via unspecified vectors.

Page 1 of 2