Vulnerability Name: | CVE-2013-4062 (CCN-86586) | ||||||||
Assigned: | 2013-09-03 | ||||||||
Published: | 2013-09-03 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | IBM Rational Policy Tester 8.5 before 8.5.0.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof Jazz Team servers, obtain sensitive information, and modify the client-server data stream via a crafted certificate. | ||||||||
CVSS v3 Severity: | 4.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
2.7 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-310 | ||||||||
Vulnerability Consequences: | Other | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-4062 Source: CCN Type: IBM Security Bulletin 1648481 Multiple vulnerabilities in IBM Rational Policy Tester (CVE-2013-0531, CVE-2013-0440, CVE-2013-4062, CVE-2013-4061, CVE-2013-2407) Source: CONFIRM Type: UNKNOWN http://www-01.ibm.com/support/docview.wss?uid=swg21648481 Source: CCN Type: IBM Security Bulletin 1653287 Multiple vulnerabilities in IBM Security AppScan Enterprise (CVE-2013-4062, CVE-2013-4061, CVE-2013-5430, CVE-2013-3989) Source: CCN Type: OSVDB ID: 96978 IBM Rational Policy Tester Jazz Team Server SSL Certificate Validation MitM Spoofing Weakness Source: CCN Type: BID-62191 IBM Rational Policy Tester CVE-2013-4062 SSL Certificate Validation Spoofing Vulnerability Source: XF Type: UNKNOWN appscan-cve20134062-invalid-cert(86586) Source: XF Type: UNKNOWN policytester-cve20134062-jazz-ssl(86586) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |