Description
The file-copying functionality in IBM Sterling Connect:Direct 3.8.00, 4.0.00, and 4.1.0 for UNIX on AIX 6.1 through 7.1 uses incorrect privileges, which allows local users to bypass filesystem read permissions and write permissions by leveraging authentication to the Connect:Direct product.
References (3)
Core 3
Core References
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IC86449
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21637561
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/84016
Scores
EPSS
0.0032
EPSS Percentile
24.1%
Details
CWE
CWE-264
Status
published
Products (3)
ibm/sterling_connect
3.8.00
ibm/sterling_connect
4.0.00
ibm/sterling_connect
4.1.0.0
Published
May 28, 2013
Tracked Since
Feb 18, 2026