IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during use of the Manual Explore Proxy feature, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary certificate.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21620759 | patch vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg21620760 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/74142 | vdb entry |