Vulnerability Description
IBM Sterling Connect:Direct for OpenVMS 3.4.00, 3.4.01, 3.5.00, 3.6.0, and 3.6.0.1 allow remote attackers to have unspecified impact by leveraging failure to reject client requests for an unencrypted session when used as the server in a TCP/IP session and configured for SSL encryption with the client. IBM X-Force ID: 86138.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Sterling Connect | 3.4.0.0 |
Related Weaknesses (CWE)
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86138VDB EntryVendor Advisory
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-sterling-connectdirect-forVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86138VDB EntryVendor Advisory
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-sterling-connectdirect-forVendor Advisory
FAQ
What is CVE-2013-4035?
CVE-2013-4035 is a vulnerability with a CVSS score of 7.3 (HIGH). IBM Sterling Connect:Direct for OpenVMS 3.4.00, 3.4.01, 3.5.00, 3.6.0, and 3.6.0.1 allow remote attackers to have unspecified impact by leveraging failure to reject client requests for an unencrypted ...
How severe is CVE-2013-4035?
CVE-2013-4035 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-4035?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Sterling Connect.