5.8
CVSSv2

CVE-2014-8918

Published: 02/02/2015 Updated: 08/09/2017
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

IBM Security AppScan Standard 8.x and 9.x prior to 9.0.1.1 FP1 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle malicious users to spoof servers and obtain sensitive information via a crafted certificate.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm security appscan 8.0.0.1

ibm security appscan 8.0.0.2

ibm security appscan 8.8.0.0

ibm security appscan 9.0.0.0

ibm security appscan 8.0.0.3

ibm security appscan 8.5.0.0

ibm security appscan 9.0.0.1

ibm security appscan 9.0.1.0

ibm security appscan 8.0.0.0

ibm security appscan 8.6.0.1

ibm security appscan 8.7.0.0

ibm security appscan 8.7.0.1

ibm security appscan 8.5.0.1

ibm security appscan 8.6.0.0

ibm security appscan 9.0.1.1