Our Products:   CompleteFTP  edtFTPnet/Free  edtFTPnet/PRO  edtFTPj/Free  edtFTPj/PRO
0 votes
38 views
ago in Java FTP by (140 points)
Why internal BDH (security binary) scan highlighting vulnerability in com.enterprisedt.net.j2ssh.openssh ?

Please confirm if there is any fix in latest version jar. We may take decision to purchase.
ago by (165k points)
Please provide us with more details.
ago by (140 points)
We are using edtftpj-pro-7.4.0 version licence one in our project.
Security team is run BDH scan that is one of the security scan you can google it.
While running it's highlighting volnarability in your jar 7.4.0. as mentioned above
ago by (165k points)
Please post the actual vulnerability details - this doesn't provide us with enough information.
ago by (9.4k points)
Have you tried upgrading, or at least testing with the latest version? There have been 13 versions since version 7.4.0., so your version is pretty out of date.
ago by (140 points)
Please can confirm if we include latest jar this issue will resolve? Because it's cost effective right ?
ago by (9.4k points)
You can download the trial to a different "test"machine - please don't download to the same machine as your paid version as it will cause issues. If the trial (latest version) works then you know that upgrading will help.
ago by (140 points)
I have cross check again with security team they are mentioning like

"BDH does not recognize this library"
com.enterprisedt.net.j2ssh.openssh
ago by (165k points)
If the only message is that BDH does not recognize this library, then it's not providing any security vulnerability.

Please log in or register to answer this question.

Categories

...