First published: Thu May 03 2012(Updated: )
The Enterprise Console client in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational AppScan | =5.2 | |
IBM Rational AppScan | =5.4 | |
IBM Rational AppScan | =5.5.0 | |
IBM Rational AppScan | =5.5.0.1 | |
IBM Rational AppScan | =5.5.0.2 | |
IBM Rational AppScan | =5.6.0 | |
IBM Rational AppScan | =5.6.0.3 | |
IBM Rational AppScan | =8.0.0 | |
IBM Rational AppScan | =8.0.0.1 | |
IBM Rational AppScan | =8.0.0.2 | |
IBM Rational AppScan | =8.0.0.3 | |
IBM Rational AppScan | =8.0.1 | |
IBM Rational AppScan | =8.0.1.1 | |
IBM Rational AppScan | =8.5.0 | |
IBM Rational AppScan | =8.5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0732 is rated as a medium severity vulnerability due to its potential for allow man-in-the-middle attacks.
To fix CVE-2012-0732, upgrade your IBM Rational AppScan Enterprise version to 8.5.0.1 or later.
The impact of CVE-2012-0732 includes exposing sensitive information through improper verification of SSL certificates by the client.
If you are using IBM Rational AppScan Enterprise versions lower than 8.5.0.1, you are vulnerable to CVE-2012-0732.
CVE-2012-0732 affects users of IBM Rational AppScan Enterprise versions 5.x and 8.x prior to 8.5.0.1.