Man-in-the-middle vulnerability in Micro Focus Self Service Password Reset, affecting all versions prior to 4.4.0.4. The vulnerability could exploit invalid certificate validation and may result in a man-in-the-middle attack.
The product does not validate, or incorrectly validates, a certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Netiq_self_service_password_reset | Microfocus | * | 4.3 (including) |
Netiq_self_service_password_reset | Microfocus | 4.4 (including) | 4.4 (including) |
Netiq_self_service_password_reset | Microfocus | 4.4-update_1 (including) | 4.4-update_1 (including) |
Netiq_self_service_password_reset | Microfocus | 4.4-update_2 (including) | 4.4-update_2 (including) |
Netiq_self_service_password_reset | Microfocus | 4.4-update_3 (including) | 4.4-update_3 (including) |