CVE-2016-1186: Medium severity cybozu kintone vulnerability
Published Apr 21, 2017
·Updated
Kintone mobile for Android 1.0.0 through 1.0.5 does not verify SSL server certificates.
Affected Software
6 affected components
Cybozu Kintone Android=1.0.0
Cybozu Kintone Android=1.0.1
Cybozu Kintone Android=1.0.2
Cybozu Kintone Android=1.0.3
Cybozu Kintone Android=1.0.4
Cybozu Kintone Android=1.0.5
Event History
Apr 21, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1186?
CVE-2016-1186 has been rated as a high severity vulnerability due to the lack of SSL server certificate verification.
2
How do I fix CVE-2016-1186?
To resolve CVE-2016-1186, upgrade Kintone mobile for Android to version 1.0.6 or later, where the SSL verification issue is addressed.
3
Which versions of Kintone are affected by CVE-2016-1186?
CVE-2016-1186 affects Kintone mobile for Android versions 1.0.0 through 1.0.5.
4
What impact does CVE-2016-1186 have on users?
CVE-2016-1186 can allow attackers to perform man-in-the-middle attacks by bypassing SSL certificate verification.
5
Is there a workaround for CVE-2016-1186 before I can upgrade?
There are no effective workarounds for CVE-2016-1186, and users are advised to update their application as soon as possible.