First published: Mon Sep 09 2013(Updated: )
IBM Rational Policy Tester 8.5 before 8.5.0.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof Jazz Team servers, obtain sensitive information, and modify the client-server data stream via a crafted certificate.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational Policy Tester | =8.5.0.0 | |
IBM Rational Policy Tester | =8.5.0.1 | |
IBM Rational Policy Tester | =8.5.0.2 | |
IBM Rational Policy Tester | =8.5.0.3 | |
IBM Rational Policy Tester | =8.5.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4062 is classified as a high severity vulnerability due to its potential for man-in-the-middle attacks.
To fix CVE-2013-4062, upgrade to IBM Rational Policy Tester version 8.5.0.5 or later.
CVE-2013-4062 affects IBM Rational Policy Tester versions 8.5.0.0 to 8.5.0.4.
CVE-2013-4062 allows attackers to perform man-in-the-middle attacks, which can result in data theft and modification.
The primary mitigation for CVE-2013-4062 is to ensure that you upgrade to the patched version 8.5.0.5 or higher.