VYPR
High severity7.4NVD Advisory· Published Oct 10, 2017· Updated May 13, 2026

CVE-2015-2988

CVE-2015-2988

Description

Rakuten card App for iOS 5.2.0 through 5.2.4 does not verify SSL certificates which might allow remote attackers to execute man-in-the-middle attacks.

Affected products

5
  • cpe:2.3:a:rakutencard:rakuten_card:5.2.0:*:*:*:*:iphone_os:*:*+ 4 more
    • cpe:2.3:a:rakutencard:rakuten_card:5.2.0:*:*:*:*:iphone_os:*:*
    • cpe:2.3:a:rakutencard:rakuten_card:5.2.1:*:*:*:*:iphone_os:*:*
    • cpe:2.3:a:rakutencard:rakuten_card:5.2.2:*:*:*:*:iphone_os:*:*
    • cpe:2.3:a:rakutencard:rakuten_card:5.2.3:*:*:*:*:iphone_os:*:*
    • cpe:2.3:a:rakutencard:rakuten_card:5.2.4:*:*:*:*:iphone_os:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.