CVE-2013-2989

IBM Sterling Connect:Direct <4.2 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The file-copying functionality in IBM Sterling Connect:Direct 3.8.00, 4.0.00, and 4.1.0 for UNIX on AIX 6.1 through 7.1 uses incorrect privileges, which allows local users to bypass filesystem read permissions and write permissions by leveraging authentication to the Connect:Direct product.

References (3)

Core 3
Core References
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IC86449
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21637561
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/84016

Scores

EPSS 0.0032
EPSS Percentile 24.1%

Details

CWE
CWE-264
Status published
Products (3)
ibm/sterling_connect 3.8.00
ibm/sterling_connect 4.0.00
ibm/sterling_connect 4.1.0.0
Published May 28, 2013
Tracked Since Feb 18, 2026