Gizmo 3.1.0.79 on Linux does not verify a server's SSL certificate, which allows remote servers to obtain the credentials of arbitrary users via a spoofed certificate.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://secunia.com/advisories/35628 | third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/51399 | vdb entry |
http://www.securityfocus.com/bid/35508 | vdb entry |
http://www.securityfocus.com/archive/1/504572/100/0/threaded | mailing list |