CVE Published: 26/07/2018 |
CVE Updated: 05/08/2024 |
CVE Year: 2018 Source: jpcert |
Vendor: DHC Corporation |
Product: DHC Online Shop App for Android Status : PUBLISHED
CVE-2018-0622 Description
The DHC Online Shop App for Android version 3.2.0 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.