5.8
CVSSv2

CVE-2012-5781

Published: 04/11/2012 Updated: 10/05/2021
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

Amazon Elastic Load Balancing API Tools does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle malicious users to spoof SSL servers via an arbitrary valid certificate, related to overriding the default JDK X509TrustManager.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

amazon elastic load balancing 1.0.12.0

amazon elastic load balancing 1.0.10.0

amazon elastic load balancing 1.0.3.4

amazon elastic load balancing 1.0

amazon elastic load balancing -

amazon elastic load balancing 1.0.17.0

amazon elastic load balancing 1.0.15.1

amazon elastic load balancing 1.0.14.3

amazon elastic load balancing 1.0.11.1

amazon elastic load balancing 1.0.9.3