Skip to Main Content
ARIS - SHARE YOUR IDEAS
How can we make ARIS better?
Status Open for voting
Created by Guest
Created on Mar 13, 2022

Application Sends Sensitive Data Unencrypted via email

The finding impacts on the Web UI

Confidential data (such as electronic statements) is delivered to the user via an insecure channel such as email. This exposes potentially sensitive data in plaintext over local and intermediary networks. This traffic can be viewed and intercepted by malicious third parties


Affected Hosts/URLs:

citi.ariscloud.com:443


Example -

The permanent password displayed in clear text in the email sent to the user


Brainstorm ID 7798
Created on Brainstorm 03/24/2020 09:50 AM
  • +2