The PayPal app before 3.0.1 for iOS does not verify...
Vulnerability Description
The PayPal app before 3.0.1 for iOS does not verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof a PayPal web server via an arbitrary certificate.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-4211
Credits & Attribution
No credits recorded in the NVD database.
References
- http://viaforensics.com/press-releases/viaforensics-uncovers-paypal-application-vulnerability.html
- http://www.vupen.com/english/advisories/2010/2887
- http://news.cnet.com/8301-27080_3-20021730-245.html
- http://www.securityfocus.com/bid/44657
- http://online.wsj.com/article/SB10001424052748703506904575592782874885808.html
- http://itunes.apple.com/us/app/paypal/id283646709
- http://viaforensics.com/security/viaforensics-uncovers-significant-vulnerability-paypal-iphone.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/63002
Affected Vendor
ebay
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.