PT-2018-4096 · Ibm · Ibm Sterling Connect:Direct
Published
2018-05-01
·
Updated
2018-06-07
·
CVE-2013-4035
CVSS v2.0
4.1
Medium
| Vector | AV:A/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Sterling Connect:Direct for OpenVMS versions 3.4.00 through 3.6.0.1
Description
The issue allows remote attackers to have an unspecified impact by leveraging the failure to reject client requests for an unencrypted session when used as the server in a TCP/IP session and configured for SSL encryption with the client.
Recommendations
For versions 3.4.00 through 3.6.0.1, consider configuring the server to reject client requests for unencrypted sessions to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Sterling Connect:Direct