CVE Published: 09/01/2019 |
CVE Updated: 05/08/2024 |
CVE Year: 2018 Source: jpcert |
Vendor: Mizuho Bank, Ltd. |
Product: Mizuho Direct App for Android Status : PUBLISHED
CVE-2018-16179 Description
The Mizuho Direct App for Android version 3.13.0 and earlier does not verify server certificates, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.