eBay Payflow SDK SSL Certificate Validation Security Bypass Vulnerability
BID:56446
Info
eBay Payflow SDK SSL Certificate Validation Security Bypass Vulnerability
| Bugtraq ID: | 56446 |
| Class: | Design Error |
| CVE: |
CVE-2012-5789 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 08 2012 12:00AM |
| Updated: | Nov 08 2012 12:00AM |
| Credit: | Reported at the ACM CCS 2012 conference |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
eBay Payflow SDK SSL Certificate Validation Security Bypass Vulnerability
Payflow SDK is prone to a security-bypass vulnerability because the application fails to properly validate SSL certificates from the server.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
Payflow SDK is prone to a security-bypass vulnerability because the application fails to properly validate SSL certificates from the server.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
References
eBay Payflow SDK SSL Certificate Validation Security Bypass Vulnerability
References:
References: