SFTPPlus uses OpenSSL only for FTPS protocol. SFTP protocol is not affected by this bug.

OpenSSL Heartbleed bug and SFTPPlus

On Unix and Linux, SFTPPlus software use the OpenSSL library provided by the operating system. Unix and Linux operating system supported by SFTPPlus (RHEL 4, RHEL5, RHEL6, SLES 11, AIX 5.3) are not affected …

SFTPPlus Team is pleased to announce the latest release of SFTPPlus Server, version 2.4.0.

This version adds support for uploading files with unlimited size over HTTP and HTTPS. This puts HTTP/HTTPS service capabilities in line with SFTP and FTP/FTPS services.

It also add support for symbolic …

SFTPPlus Team is pleased to announce the latest release of SFTPPlus Server, version 2.3.0.

This version adds support for HTTP and HTTPS as protocols for file transfer services. The HTTP/HTTPS/HTML implementation is compabitle with any web browser and transfer can be automated using command line clients …

SFTPPlus Team is pleased to announce the latest release of SFTPPlus Server, version 2.2.0.

This version add support for IBM AIX operating system starting with version 5.3 , os level 6.

It also add support for authenticating global accounts inside SFTPPlus WebAdmin using SSH keys.

For more details …

SFTPPlus Team is pleased to announce the latest release of SFTPPlus Server, version 2.1.0

Main new features are:

  • A graphical user interface for managing the SFTPPlus Server.
  • Support for FTP APPE command. For more details consult the IETF RFC 959.
  • Globbing for FTP NLST and LIST commands. Globbing …

Monday, 22 April 2013 - we have discovered a security vulnerability affecting SFTPPlus Server version 1.6, 1.7 and 1.8.

Due to an error in checking the SSH key signature, when SSH key authentication is used for a SFTP transfer, a user can obtain server access by using only …

Last week a bug was discovered in all OpenSSL version. This bug can cause various security issues.

More information about the original vulnerability report for OpenSSL can be found from National Cyber Awareness System

A fix was already provided by the OpenSSL team as of 24 of April 2012.

Please …