CVE-2013-4035

HIGH

IBM Sterling Connect:Direct for OpenVMS 3.4.00-3.6.0.1 - Unencrypted Data Transfer via SSL Configuration Bypass

Title source: llm
STIX 2.1

Description

IBM Sterling Connect:Direct for OpenVMS 3.4.00, 3.4.01, 3.5.00, 3.6.0, and 3.6.0.1 allow remote attackers to have unspecified impact by leveraging failure to reject client requests for an unencrypted session when used as the server in a TCP/IP session and configured for SSL encryption with the client. IBM X-Force ID: 86138.

Scores

CVSS v3 7.3
EPSS 0.0047
EPSS Percentile 38.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-310
Status published
Products (5)
ibm/sterling_connect 3.4.0.0
ibm/sterling_connect 3.4.0.1
ibm/sterling_connect 3.5.0.0
ibm/sterling_connect 3.6.0
ibm/sterling_connect 3.6.0.1
Published May 01, 2018
Tracked Since Feb 18, 2026