VendorsIBMsterling_connect%5Call versions
Vulnerabilities

IBM Sterling Connect:Direct

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19CVEs
CVE-2020-4587
IBM Sterling Connect:Direct for UNIX 4.2.0, 4.3.0, 6.0.0, and 6.1.0 is vulnerable to a stack based buffer ovreflow, caused by improper bounds checking. A local attacker could manipulate CD UNIX to obtain root provileges. IBM X-Force ID: 184578.
Published 2020-08-24 · Modified
8.4EPSS 0.003
CVE-2020-4767
IBM Sterling Connect Direct for Microsoft Windows 4.7, 4.8, 6.0, and 6.1 could allow a remote attacker to cause a denial of service, caused by a buffer over-read. Bysending a specially crafted request, the attacker could cause the application to crash. IBM X-Force ID: 188906.
Published 2020-10-28 · Modified
7.5EPSS 0.016
CVE-2021-38890
IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 209507.
Published 2021-11-23 · Modified
7.5EPSS 0.016
CVE-2023-32331
IBM Connect:Express for UNIX denial of service
Published 2024-03-04 · Analyzed
7.5EPSS 0.007
CVE-2021-38891
IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 209508.
Published 2021-11-23 · Modified
7.5EPSS 0.007
CVE-2021-38933
IBM Sterling Connect:Express for UNIX information disclosure
Published 2023-07-19 · Modified
7.5EPSS 0.004
CVE-2018-1903
IBM Sterling Connect:Direct for UNIX 4.2.0, 4.3.0, and 6.0.0 could allow a user with restricted sudo access on a system to manipulate CD UNIX to gain full sudo access. IBM X-Force ID: 152532.
Published 2019-04-10 · Modified
7.2EPSS 0.004
CVE-2025-36137
IBM Sterling Connect:Direct for UNIX command execution
Published 2025-10-30 · Analyzed
7.2EPSS 0.003
CVE-2023-29260
IBM Sterling Connect:Express for UNIX server-side request forgery
Published 2023-07-19 · Modified
6.5EPSS 0.003
CVE-2025-36065
Multiple vulnerabilities were addressed in IBM Sterling Connect:Express for UNIX.
Published 2026-01-20 · Analyzed
6.5EPSS 0.002
CVE-2025-36063
Multiple vulnerabilities were addressed in IBM Sterling Connect:Express for UNIX.
Published 2026-01-20 · Analyzed
6.5EPSS 0.002
CVE-2025-36115
Multiple vulnerabilities were addressed in IBM Sterling Connect:Express for UNIX.
Published 2026-01-20 · Analyzed
6.5EPSS 0.002
CVE-2025-36066
Multiple vulnerabilities were addressed in IBM Sterling Connect:Express for UNIX.
Published 2026-01-20 · Analyzed
6.1EPSS 0.002
CVE-2025-36064
IBM Sterling Connect:Express for Microsoft Windows information disclosure
Published 2025-09-22 · Analyzed
5.9EPSS 0.005
CVE-2025-36113
Multiple vulnerabilities were addressed in IBM Sterling Connect:Express for UNIX.
Published 2026-01-20 · Analyzed
5.4EPSS 0.002
CVE-2023-29259
IBM Sterling Connect:Express for UNIX information disclosure
Published 2023-07-19 · Modified
5.3EPSS 0.005
CVE-2016-5991
IBM Sterling Connect:Direct 4.5.00, 4.5.01, 4.6.0 before 4.6.0.6 iFix008, and 4.7.0 before 4.7.0.4 on Windows allows local users to gain privileges via unspecified vectors.
Published 2016-11-25 · Modified
4.5EPSS 0.003
CVE-2016-0380
IBM Sterling Connect:Direct for Unix 4.1.0 before 4.1.0.4 iFix073 and 4.2.0 before 4.2.0.4 iFix003 uses default file permissions of 0664, which allows local users to obtain sensitive information via standard filesystem operations.
Published 2016-08-08 · Modified
3.3EPSS 0.003
CVE-2016-5992
IBM Sterling Connect:Direct 4.5.00, 4.5.01, 4.6.0 before 4.6.0.6 iFix008, and 4.7.0 before 4.7.0.4 on Windows allows local users to cause a denial of service via unspecified vectors.
Published 2016-11-25 · Modified
2.5EPSS 0.003