PT-2014-3206 · Opentext · Opentext Exceed Ondemand
Krzysztof Kotowicz
+1
·
Publicado
2014-05-19
·
Atualizado
2014-05-19
·
CVE-2013-6807
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
OpenText Exceed OnDemand (EoD) version 8
Description
The issue allows man-in-the-middle attackers to bypass server certificate validation, redirect a connection, and obtain sensitive information via crafted responses, due to the client supporting anonymous ciphers by default.
Recommendations
For OpenText Exceed OnDemand (EoD) version 8, consider disabling the support for anonymous ciphers to prevent man-in-the-middle attacks.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Opentext Exceed Ondemand