X.509 Certificate Verification Flaw in IBM Rational Policy Tester
CVE-2013-4062
Currently unrated
Summary
IBM Rational Policy Tester 8.5 prior to version 8.5.0.5 is susceptible to a security vulnerability that arises from its failure to properly verify X.509 certificates from SSL servers. This oversight can be exploited by man-in-the-middle attackers, enabling them to impersonate Jazz Team servers. Consequently, these attackers can intercept sensitive data and manipulate the client-server communication by employing a maliciously crafted certificate. This vulnerability poses significant risks to the integrity and confidentiality of data exchanged between clients and servers.
References
Timeline
Vulnerability published
Vulnerability Reserved