VulnerabilityModified
CVE-2018-2460
This allows attacker to do MITM attack.
MEDIUM 5.9EPSS 0.77%
Does this matter?
Lower severity and a low EPSS score (0.77%). Track it; it rarely justifies an emergency change on its own.
Description
SAP Business One Android application, version 1.2, does not verify the certificate properly for HTTPS connection. This allows attacker to do MITM attack.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.77% probability · 53th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295
- Affected
- sap/business one
- Source
- cna@sap.com
References
- http://www.securityfocus.com/bid/105309Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2682503Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=499356993Vendor Advisory
- http://www.securityfocus.com/bid/105309Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2682503Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=499356993Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.