CVE

Id
99232  
CVE No.
CVE-2017-2412  
Status
Candidate  
Description
An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "iTunes Store" component. It allows man-in-the-middle attackers to modify the client-server data stream to iTunes sandbox web services by leveraging use of cleartext HTTP.  
Phase
Assigned (20161201)  
Votes
None (candidate not yet proposed)  
Comments