nCipher payShield SPP Library Bad Request Verification Vulnerability
BID:9422
Info
nCipher payShield SPP Library Bad Request Verification Vulnerability
| Bugtraq ID: | 9422 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jan 14 2004 12:00AM |
| Updated: | Jan 14 2004 12:00AM |
| Credit: | This vulnerability was announced by the vendor. |
| Vulnerable: |
nCipher payShield SPP Library 1.6.18 nCipher payShield SPP Library 1.5.18 nCipher payShield SPP Library 1.3.12 |
| Not Vulnerable: | |
Discussion
nCipher payShield SPP Library Bad Request Verification Vulnerability
payShield has been reported prone to a vulnerability that may result in bad requests being verified. This issue has been reported to present itself in the host-side library and applications only. It has been reported that the vulnerability exists because the status of a command that is being processed when a modules query is triggered may be lost.
payShield has been reported prone to a vulnerability that may result in bad requests being verified. This issue has been reported to present itself in the host-side library and applications only. It has been reported that the vulnerability exists because the status of a command that is being processed when a modules query is triggered may be lost.
Exploit / POC
nCipher payShield SPP Library Bad Request Verification Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
nCipher payShield SPP Library Bad Request Verification Vulnerability
Solution:
The vendor has advised that developers who are potentially affected by this vulnerability, update their software and re-link to the fixed library as soon as possible.
Solution:
The vendor has advised that developers who are potentially affected by this vulnerability, update their software and re-link to the fixed library as soon as possible.
References
nCipher payShield SPP Library Bad Request Verification Vulnerability
References:
References:
- nCipher Homepage (nCipher)
- payShield library may verify bad requests (nCipher)
- nCipher Advisory #8: payShield library may verify bad requests (nCipher Support
)