IBM Sterling Connect:Direct for OpenVMS 3.4.00, 3.4.01, 3.5.00, 3.6.0, and 3.6.0.1 allow remote attackers to have unspecified impact by leveraging failure to reject client requests for an unencrypted session when used as the server in a TCP/IP session and configured for SSL encryption with the client. IBM X-Force ID: 86138.
2018-05-01T18:29:00.243
2024-11-21T01:54:45.630
Modified
CVSSv3.0: 7.3 (HIGH)
AV:A/AC:L/Au:S/C:P/I:P/A:N
5.1
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | sterling_connect | 3.4.0.0 | Yes |
Application | ibm | sterling_connect | 3.4.0.1 | Yes |
Application | ibm | sterling_connect | 3.5.0.0 | Yes |
Application | ibm | sterling_connect | 3.6.0 | Yes |
Application | ibm | sterling_connect | 3.6.0.1 | Yes |