A vulnerability in the encryption implementation of EBICS...
High severity
Unreviewed
Published
Apr 15, 2022
to the GitHub Advisory Database
•
Updated Aug 2, 2023
Description
Published by the National Vulnerability Database
Apr 14, 2022
Published to the GitHub Advisory Database
Apr 15, 2022
Last updated
Aug 2, 2023
A vulnerability in the encryption implementation of EBICS messages in the open source librairy ebics-java/ebics-java-client allows an attacker sniffing network traffic to decrypt EBICS payloads. This issue affects: ebics-java/ebics-java-client versions prior to 1.2.
References