Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-63m8-v7w4-mcq7

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during use of the Manual Explore Proxy feature, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary certificate.

IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during use of the Manual Explore Proxy feature, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary certificate.

EPSS

Процентиль: 34%
0.00139
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
около 13 лет назад

IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during use of the Manual Explore Proxy feature, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary certificate.

EPSS

Процентиль: 34%
0.00139
Низкий

Дефекты

CWE-20