Security Advisory

CVE-2017-2412

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-04-02 01:36:00
Last updated 2024-08-05 13:55:05
Assigner apple
CVSS score not scored
State PUBLISHED

Description

An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "iTunes Store" component. It allows man-in-the-middle attackers to modify the client-server data stream to iTunes sandbox web services by leveraging use of cleartext HTTP.