IBM Security AppScan Enterprise prior to 8.6.0.2 and Rational Policy Tester prior to 8.5.0.3 do not validate X.509 certificates during scanning, which allows man-in-the-middle malicious users to spoof SSL servers via an arbitrary certificate.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ibm security appscan 8.0.0.0 |
||
ibm security appscan 6.1.1.0 |
||
ibm security appscan 6.0.2.0 |
||
ibm security appscan 6.0.1.0 |
||
ibm security appscan 8.5.0.0 |
||
ibm security appscan 8.0.0.1 |
||
ibm security appscan 8.6.0.0 |
||
ibm security appscan 8.5.0.1 |
||
ibm security appscan 6.0.0.0 |
||
ibm rational policy tester 8.5.0.0 |
||
ibm rational policy tester 8.0.1.1 |
||
ibm rational policy tester 5.6.0.0 |
||
ibm rational policy tester 5.5.0.2 |
||
ibm rational policy tester 8.0.1.0 |
||
ibm rational policy tester 8.0.0.2 |
||
ibm rational policy tester 5.5.0.1 |
||
ibm rational policy tester 5.5.0.0 |
||
ibm rational policy tester |
||
ibm rational policy tester 8.5.0.1 |
||
ibm rational policy tester 5.6.0.3 |
||
ibm rational policy tester 5.6.0.2 |
||
ibm rational policy tester 5.6.0.1 |
||
ibm rational policy tester 8.0.0.1 |
||
ibm rational policy tester 8.0.0.0 |
||
ibm security appscan |