PT-2020-10459 · Heartland & Global Payments · Heartland & Global Payments Php Sdk
Oldpec
·
Published
2020-02-14
·
Updated
2024-02-14
·
CVE-2019-20455
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Heartland & Global Payments PHP SDK versions prior to 2.0.0
Description
The issue concerns the failure to enforce SSL certificate validations in the Gateways/Gateway.php file. This could potentially lead to security risks, as it may allow for man-in-the-middle attacks or other types of exploitation. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations
For versions prior to 2.0.0, update to version 2.0.0 or later to resolve the issue. As a temporary workaround, consider disabling the use of the Gateways/Gateway.php file until a patch is available. Restrict access to sensitive data handled by this file to minimize the risk of exploitation.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Heartland & Global Payments Php Sdk