PT-2014-7552 · American Express · American Express Serve
Published
2014-10-02
·
Updated
2014-11-14
·
CVE-2014-6876
CVSS v2.0
5.4
Medium
| Vector | AV:A/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
American Express Serve application version @7F0901E4
Description
The issue concerns the American Express Serve application for Android, which fails to verify X.509 certificates from SSL servers. This allows man-in-the-middle attackers to spoof servers and obtain sensitive information by using a crafted certificate.
Recommendations
For American Express Serve application version @7F0901E4, consider disabling the use of SSL connections until a patch is available that properly verifies X.509 certificates. Restrict access to sensitive information to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
American Express Serve