SAP Business One Android application, version 1.2, does not verify the certificate properly for HTTPS connection. This allows attacker to do MITM attack.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=499356993 | vendor advisory |
http://www.securityfocus.com/bid/105309 | third party advisory vdb entry |
https://launchpad.support.sap.com/#/notes/2682503 | vendor advisory permissions required |