Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Basware Banking (Maksuliikenne) before 9.10.0.0 does not encrypt communication between the client and the backend server, which allows man-in-the-middle attackers to obtain encryption keys, user credentials, and other sensitive information by sniffing the network or modify this traffic by inserting packets into the client-server data stream.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Basware Maksuliikenne 信息泄露漏洞
Vulnerability Description
Basware Banking(Maksuliikenne)是芬兰Basware公司的一套与银行建立连接对自己的金融进行管理的软件。 Basware Banking 8.90.07及之前版本中存在安全漏洞,该漏洞源于程序没有加密客户端和后端服务器之间的通信。攻击者可通过嗅探网络利用该漏洞实施中间人攻击,获取敏感信息(加密密钥,用户证书等);或通过向client-server数据流中插入数据包利用该漏洞修改该流量。
CVSS Information
N/A
Vulnerability Type
N/A