PKCS #12 File Format Vulnerability in IBM Global Security Kit Products
CVE-2012-2203
Currently unrated
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 8 August 2012
Summary
The IBM Global Security Kit (GSKit) suffers from a file integrity vulnerability due to its use of the PKCS #12 file format for certificate objects. This flaw allows remote attackers to potentially spoof SSL servers by inserting an arbitrary root Certification Authority (CA) certificate, thereby compromising the intended security measures. Organizations using affected versions of GSKit are advised to update their systems to the latest version to mitigate this risk.
References
Timeline
Vulnerability published
Vulnerability Reserved