PT-2015-4988 · Basware · Basware Banking
Samuel Lavitt
·
Publicado
2015-08-31
·
Atualizado
2015-08-31
·
CVE-2015-0943
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Basware Banking (Maksuliikenne) versions prior to 9.10.0.0
Description
The issue allows man-in-the-middle attackers to obtain sensitive information, including encryption keys and user credentials, by sniffing the network or modifying the traffic. This is possible because communication between the client and the backend server is not encrypted.
Recommendations
For versions prior to 9.10.0.0, update to version 9.10.0.0 or later to ensure encryption of communication between the client and the backend server.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Basware Banking