There are multiple vulnerabilities in IBM® Runtime Environment Java™ Versions 7.0.9.30 and 6.0.16.20 that are used by IBM Sterling Connect:Direct FTP+. These issues were disclosed as part of the IBM Java SDK updates in April 2016.
CVEID: CVE-2016-3426** *DESCRIPTION: An unspecified vulnerability related to the JCE component could allow a remote attacker to obtain sensitive information resulting in a partial confidentiality impact using unknown attack vectors.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/112457 for the current score
CVSS Environmental Score: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N)
If you run your own Java code using the IBM Java Runtime delivered with this product, you should evaluate your code to determine whether the complete list of vulnerabilities are applicable to your code. For a complete list of vulnerabilities please refer to the Reference section for more information.
IBM Sterling Connect:Direct FTP+ 1.3.0
V.R.M
| APAR|Remediation
—|—|—
1.3.0| IT17607| Apply 1.3.0 Fix005, available on Fix Central.
None