First published: Fri Apr 21 2017(Updated: )
Kintone mobile for Android 1.0.0 through 1.0.5 does not verify SSL server certificates.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Cybozu Kintone | =1.0.0 | |
Cybozu Kintone | =1.0.1 | |
Cybozu Kintone | =1.0.2 | |
Cybozu Kintone | =1.0.3 | |
Cybozu Kintone | =1.0.4 | |
Cybozu Kintone | =1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1186 has been rated as a high severity vulnerability due to the lack of SSL server certificate verification.
To resolve CVE-2016-1186, upgrade Kintone mobile for Android to version 1.0.6 or later, where the SSL verification issue is addressed.
CVE-2016-1186 affects Kintone mobile for Android versions 1.0.0 through 1.0.5.
CVE-2016-1186 can allow attackers to perform man-in-the-middle attacks by bypassing SSL certificate verification.
There are no effective workarounds for CVE-2016-1186, and users are advised to update their application as soon as possible.