The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user's network traffic could bypass the application's use of SSL/TLS encryption and use the application as a platform for attacks against its users.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: SolarWinds
Published: 2022-11-23T16:48:18.061230Z
Updated: 2024-08-04T00:33:51.305Z
Reserved: 2021-06-22T00:00:00
Link: CVE-2021-35246
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-11-23T17:15:09.943
Modified: 2024-11-21T06:12:08.733
Link: CVE-2021-35246
Redhat
No data.