📦 Sterling Connect\

by Ibm

🔍 What is Sterling Connect\?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-36137

HIGH CVSS 7.2 Oct 30, 2025

This vulnerability in IBM Sterling Connect Direct for Unix allows CCD users with existing privileges to escalate their permissions further through maintenance task assignments. It affects users of spe...

CVE-2023-32331

HIGH CVSS 7.5 Mar 4, 2024

CVE-2023-32331 is a buffer overflow vulnerability in IBM Connect:Express for UNIX 1.5.0 that allows remote attackers to cause denial of service through the browser UI. Organizations running this speci...

CVE-2021-38890

HIGH CVSS 7.5 Nov 23, 2021

IBM Sterling Connect:Direct Web Services has an inadequate account lockout mechanism that allows remote attackers to perform brute-force attacks against user credentials. This affects versions 1.0 and...

CVE-2025-36063

MEDIUM CVSS 6.3 Jan 20, 2026

IBM Sterling Connect:Express Adapter for Sterling B2B Integrator fails to properly invalidate user sessions after logout, allowing authenticated users to potentially reuse old session tokens to impers...

CVE-2025-36065

MEDIUM CVSS 6.3 Jan 20, 2026

IBM Sterling Connect:Express Adapter for Sterling B2B Integrator versions 5.2.0.00 through 5.2.0.12 fails to properly invalidate user sessions when a browser is closed, allowing authenticated users to...

CVE-2025-36066

MEDIUM CVSS 6.1 Jan 20, 2026

This CVE describes a cross-site scripting (XSS) vulnerability in IBM Sterling Connect:Express Adapter for Sterling B2B Integrator. Unauthenticated attackers can inject malicious JavaScript into the we...

CVE-2025-36113

MEDIUM CVSS 5.4 Jan 20, 2026

This cross-site scripting vulnerability in IBM Sterling Connect:Express Adapter allows authenticated users to inject malicious JavaScript into the web interface. Attackers could steal session credenti...

CVE-2025-36115

MEDIUM CVSS 6.3 Jan 20, 2026

IBM Sterling Connect:Express Adapter for Sterling B2B Integrator versions 5.2.0.00 through 5.2.0.12 fails to properly invalidate session IDs after use, allowing authenticated users to hijack other use...