The Bank of Tokyo-Mitsubishi UFJ, Ltd. App for Android ver5.3.1, ver5.2.2 and earlier allow a man-in-the-middle attacker to downgrade the communication between the app and the server from TLS v1.2 to SSL v3.0, which may result in the attacker to eavesdrop on an encrypted communication.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2017-08-02T16:00:00

Updated: 2024-08-06T02:04:56.096Z

Reserved: 2016-09-09T00:00:00

Link: CVE-2016-7812

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2017-08-02T16:29:00.177

Modified: 2017-08-07T22:04:36.843

Link: CVE-2016-7812

cve-icon Redhat

No data.