Show filters
24 Total Results
Displaying 11-20 of 24
Sort by:
Attacker Value
Unknown
CVE-2020-4747
Disclosure Date: December 14, 2020 (last updated February 22, 2025)
IBM Connect:Direct for UNIX 6.1.0, 6.0.0, 4.3.0, and 4.2.0 can allow a local or remote user to obtain an authenticated CLI session due to improper authentication methods. IBM X-Force ID: 188516.
0
Attacker Value
Unknown
CVE-2020-4767
Disclosure Date: October 27, 2020 (last updated February 22, 2025)
IBM Sterling Connect Direct for Microsoft Windows 4.7, 4.8, 6.0, and 6.1 could allow a remote attacker to cause a denial of service, caused by a buffer over-read. Bysending a specially crafted request, the attacker could cause the application to crash. IBM X-Force ID: 188906.
0
Attacker Value
Unknown
CVE-2020-4587
Disclosure Date: August 24, 2020 (last updated February 22, 2025)
IBM Sterling Connect:Direct for UNIX 4.2.0, 4.3.0, 6.0.0, and 6.1.0 is vulnerable to a stack based buffer ovreflow, caused by improper bounds checking. A local attacker could manipulate CD UNIX to obtain root provileges. IBM X-Force ID: 184578.
0
Attacker Value
Unknown
CVE-2018-1903
Disclosure Date: April 10, 2019 (last updated November 27, 2024)
IBM Sterling Connect:Direct for UNIX 4.2.0, 4.3.0, and 6.0.0 could allow a user with restricted sudo access on a system to manipulate CD UNIX to gain full sudo access. IBM X-Force ID: 152532.
0
Attacker Value
Unknown
CVE-2016-5991
Disclosure Date: November 25, 2016 (last updated November 25, 2024)
IBM Sterling Connect:Direct 4.5.00, 4.5.01, 4.6.0 before 4.6.0.6 iFix008, and 4.7.0 before 4.7.0.4 on Windows allows local users to gain privileges via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-5992
Disclosure Date: November 25, 2016 (last updated November 25, 2024)
IBM Sterling Connect:Direct 4.5.00, 4.5.01, 4.6.0 before 4.6.0.6 iFix008, and 4.7.0 before 4.7.0.4 on Windows allows local users to cause a denial of service via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-0380
Disclosure Date: August 08, 2016 (last updated November 25, 2024)
IBM Sterling Connect:Direct for Unix 4.1.0 before 4.1.0.4 iFix073 and 4.2.0 before 4.2.0.4 iFix003 uses default file permissions of 0664, which allows local users to obtain sensitive information via standard filesystem operations.
0
Attacker Value
Unknown
CVE-2013-0527
Disclosure Date: June 21, 2013 (last updated October 05, 2023)
The Browser in IBM Sterling Connect:Direct 1.4 before 1.4.0.11 and 1.5 through 1.5.0.1 does not close pages upon the timeout of a session, which allows physically proximate attackers to obtain sensitive administrative-console information by reading the screen of an unattended workstation.
0
Attacker Value
Unknown
CVE-2013-0529
Disclosure Date: June 21, 2013 (last updated October 05, 2023)
The Browser in IBM Sterling Connect:Direct 1.4 before 1.4.0.11 and 1.5 through 1.5.0.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
0
Attacker Value
Unknown
CVE-2010-1147
Disclosure Date: April 06, 2010 (last updated October 04, 2023)
Stack-based buffer overflow in Open Direct Connect Hub (aka Open DC Hub or OpenDCHub) 0.8.1 allows remote authenticated users to execute arbitrary code via a long MyINFO message.
0