CVE-2016-7812 Vulnerability Details

  /     /     /  

CVE-2016-7812 Metadata Quick Info

CVE Published: 02/08/2017 | CVE Updated: 06/08/2024 | CVE Year: 2016
Source: jpcert | Vendor: The Bank of Tokyo-Mitsubishi UFJ, Ltd. | Product: The Bank of Tokyo-Mitsubishi UFJ, Ltd. App for Android
Status : PUBLISHED

CVE-2016-7812 Description

The Bank of Tokyo-Mitsubishi UFJ, Ltd. App for Android ver5.3.1, ver5.2.2 and earlier allow a man-in-the-middle attacker to downgrade the communication between the app and the server from TLS v1.2 to SSL v3.0, which may result in the attacker to eavesdrop on an encrypted communication.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Untrusted search path vulnerability
Source: The Bank of Tokyo-Mitsubishi UFJ, Ltd.

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).