Improper SSL Certificate Validation in Coles Credit Card Application for Android
CVE-2014-5562
Currently unrated
What is CVE-2014-5562?
The Coles Credit Card App for Android fails to adequately verify X.509 certificates from SSL servers. This security oversight allows man-in-the-middle attackers to masquerade as legitimate servers. Exploiting this vulnerability, attackers can intercept sensitive information transmitted between users and the app, leading to potential data breaches. Users of the application should ensure they are using the latest version to mitigate these risks.
