CVE-2025-14115

HIGH

IBM Sterling Connect:Direct for UNIX Container - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM Sterling Connect:Direct for UNIX Container 6.3.0.0 through 6.3.0.6 Interim Fix 016, and 6.4.0.0 through 6.4.0.3 Interim Fix 019 IBM® Sterling Connect:Direct for UNIX contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

Scores

CVSS v3 8.4
EPSS 0.0001
EPSS Percentile 1.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-798
Status published
Products (2)
IBM/Sterling Connect:Direct for UNIX Container 6.3.0.0 - 6.3.0.6 Interim Fix 016
IBM/Sterling Connect:Direct for UNIX Container 6.4.0.0 - 6.4.0.3 Interim Fix 019
Published Jan 20, 2026
Tracked Since Feb 18, 2026