The client in OpenText Exceed OnDemand (EoD) 8 supports anonymous ciphers by default, which allows man-in-the-middle attackers to bypass server certificate validation, redirect a connection, and obtain sensitive information via crafted responses.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Exceed_ondemand | Opentext | 8.0 (including) | 8.0 (including) |