CVE-2013-4035

Severity

41%

Complexity

51%

Confidentiality

81%

IBM Sterling Connect:Direct for OpenVMS 3.4.00, 3.4.01, 3.5.00, 3.6.0, and 3.6.0.1 allow remote attackers to have unspecified impact by leveraging failure to reject client requests for an unencrypted session when used as the server in a TCP/IP session and configured for SSL encryption with the client. IBM X-Force ID: 86138.

IBM Sterling Connect:Direct for OpenVMS 3.4.00, 3.4.01, 3.5.00, 3.6.0, and 3.6.0.1 allow remote attackers to have unspecified impact by leveraging failure to reject client requests for an unencrypted session when used as the server in a TCP/IP session and configured for SSL encryption with the client. IBM X-Force ID: 86138.

CVSS 3.0 Base Score 7.3. CVSS Attack Vector: adjacent_network. CVSS Attack Complexity: low. CVSS Vector: (CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

CVSS 2.0 Base Score 4.1. CVSS Attack Vector: adjacent_network. CVSS Attack Complexity: low. CVSS Vector: (AV:A/AC:L/Au:S/C:P/I:P/A:N).

Overview

Type

IBM Sterling Connect

First reported 6 years ago

2018-05-01 18:29:00

Last updated 6 years ago

2018-06-07 18:37:00

Affected Software

IBM Sterling Connect 3.4.0.0

3.4.0.0

IBM Sterling Connect 3.4.0.1

3.4.0.1

IBM Sterling Connect 3.5.0.0

3.5.0.0

IBM Sterling Connect 3.6.0

3.6.0

IBM Sterling Connect 3.6.0.1

3.6.0.1

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.