PT-2014-3206 · Opentext · Opentext Exceed Ondemand
Krzysztof Kotowicz
+1
·
Published
2014-05-19
·
Updated
2014-05-19
·
CVE-2013-6807
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
OpenText Exceed OnDemand (EoD) version 8
Description
The issue allows man-in-the-middle attackers to bypass server certificate validation, redirect a connection, and obtain sensitive information via crafted responses, due to the client supporting anonymous ciphers by default.
Recommendations
For OpenText Exceed OnDemand (EoD) version 8, consider disabling the support for anonymous ciphers to prevent man-in-the-middle attacks.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opentext Exceed Ondemand