CVE-2013-6807: Medium severity OpenText Exceed OnDemand vulnerability
The client in OpenText Exceed OnDemand (EoD) 8 supports anonymous ciphers by default, which allows man-in-the-middle attackers to bypass server certificate validation, redirect a connection, and obtain sensitive information via crafted responses.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6807?
The CVE-2013-6807 vulnerability is rated as high severity due to its potential to expose sensitive information through man-in-the-middle attacks.
How do I fix CVE-2013-6807?
To mitigate CVE-2013-6807, configure OpenText Exceed OnDemand to disable support for anonymous ciphers and ensure proper server certificate validation.
What is the impact of CVE-2013-6807?
CVE-2013-6807 allows attackers to intercept and manipulate communications between clients and servers, potentially exposing sensitive data.
Is CVE-2013-6807 specific to OpenText Exceed OnDemand?
Yes, CVE-2013-6807 specifically affects version 8.0 of OpenText Exceed OnDemand.
Can CVE-2013-6807 be exploited remotely?
Yes, CVE-2013-6807 can be exploited remotely, allowing attackers to perform man-in-the-middle attacks without physical access to the targeted network.