Description
A vulnerability in the encryption implementation of EBICS messages in the open source librairy ebics-java/ebics-java-client allows an attacker sniffing network traffic to decrypt EBICS payloads. This issue affects: ebics-java/ebics-java-client versions prior to 1.2.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Upgrade to EBICS Java Version 1.2
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-24610 | A vulnerability in the encryption implementation of EBICS messages in the open source librairy ebics-java/ebics-java-client allows an attacker sniffing network traffic to decrypt EBICS payloads. This issue affects: ebics-java/ebics-java-client versions prior to 1.2. |
References
History
No history.
Status: PUBLISHED
Assigner: NCSC.ch
Published:
Updated: 2024-08-02T23:55:24.529Z
Reserved: 2022-04-08T00:00:00.000Z
Link: CVE-2022-1279
No data.
Status : Modified
Published: 2022-04-14T08:15:06.830
Modified: 2024-11-21T06:40:24.037
Link: CVE-2022-1279
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD