WebHybridClient.java in PayPal 5.3 and earlier for Android ignores SSL errors, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/92098 | third party advisory vdb entry |
https://labs.mwrinfosecurity.com/advisories/paypal-remote-code-execution/ | third party advisory |
http://secunia.com/advisories/57351 | third party advisory |