PT-2012-6122 · Jpmorgan Chase · Chase Mobile Banking Application
Published
2012-11-04
·
Updated
2024-02-14
·
CVE-2012-5810
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Chase mobile banking application for Android (affected versions not specified)
Description
The issue concerns a failure to verify the server hostname against the domain name in the X.509 certificate's Common Name (CN) or subjectAltName field. This allows man-in-the-middle attackers to spoof SSL servers using any valid certificate, due to the override of the default X509TrustManager. It is noted that this issue was fixed in the summer of 2012.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chase Mobile Banking Application