CVE-2013-4035
Summary
| CVE | CVE-2013-4035 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-05-01 18:29:00 UTC |
| Updated | 2018-06-07 18:37:00 UTC |
| Description | IBM Sterling Connect:Direct for OpenVMS 3.4.00, 3.4.01, 3.5.00, 3.6.0, and 3.6.0.1 allow remote attackers to have unspecified impact by leveraging failure to reject client requests for an unencrypted session when used as the server in a TCP/IP session and configured for SSL encryption with the client. IBM X-Force ID: 86138. |
Risk And Classification
Problem Types: CWE-310
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Sterling Connect | 3.4.0.0 | All | All | All |
| Application | Ibm | Sterling Connect | 3.4.0.1 | All | All | All |
| Application | Ibm | Sterling Connect | 3.5.0.0 | All | All | All |
| Application | Ibm | Sterling Connect | 3.6.0 | All | All | All |
| Application | Ibm | Sterling Connect | 3.6.0.1 | All | All | All |
| Application | Ibm | Sterling Connect | 3.4.0.0 | All | All | All |
| Application | Ibm | Sterling Connect | 3.4.0.1 | All | All | All |
| Application | Ibm | Sterling Connect | 3.5.0.0 | All | All | All |
| Application | Ibm | Sterling Connect | 3.6.0 | All | All | All |
| Application | Ibm | Sterling Connect | 3.6.0.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | VDB Entry, Vendor Advisory |
| Security Bulletin: IBM Sterling Connect:Direct for OpenVMS. Unencrypted data transfers can occur even when SSL encryption is specified in the security configuration. (CVE-2013-4035) - IBM PSIRT Blog | CONFIRM | www.ibm.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.