CVE-2014-7725: Medium severity iss rally albania live 2014 vulnerability
The Rally Albania Live 2014 (aka com.wRallyAlbaniaLIVE2014) application 0.11 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7725?
CVE-2014-7725 is a high severity vulnerability due to the lack of X.509 certificate verification.
How do I fix CVE-2014-7725?
To fix CVE-2014-7725, update the Rally Albania Live application to a version that properly verifies SSL certificates.
What types of attacks can CVE-2014-7725 allow?
CVE-2014-7725 allows man-in-the-middle attacks, where attackers can spoof servers and intercept sensitive information.
Which applications are affected by CVE-2014-7725?
CVE-2014-7725 specifically affects the Rally Albania Live 2014 application version 0.11 for Android.
Is there a workaround for CVE-2014-7725?
There is no official workaround for CVE-2014-7725, and the best course of action is to update the app.