PT-2017-7933 · Cybozu · Kintone Mobile For Android
Kusano Kazuhiko
·
Publicado
2017-04-21
·
Atualizado
2017-04-26
·
CVE-2016-1186
CVSS v3.1
5.9
Média
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Kintone mobile for Android versions 1.0.0 through 1.0.5
Description
The issue is related to the failure of verifying SSL server certificates. This could potentially allow for man-in-the-middle attacks.
Recommendations
For versions 1.0.0 through 1.0.5, update to a version that properly verifies SSL server certificates to resolve the issue.
Correção
Improper Certificate Validation
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Kintone Mobile For Android