5.8
CVSSv2

CVE-2012-5784

Published: 04/11/2012 Updated: 07/11/2023
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

Apache Axis 1.4 and previous versions, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle malicious users to spoof SSL servers via an arbitrary valid certificate.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache axis 1.0

paypal mass pay -

apache axis -

apache axis 1.1

apache axis 1.2

paypal transactional information soap -

paypal payments pro -

apache axis 1.2.1

apache activemq

apache axis

apache axis 1.3

Vendor Advisories

Synopsis Moderate: axis security update Type/Severity Security Advisory: Moderate Topic Updated axis packages that fix one security issue are now available forRed Hat Enterprise Linux 5The Red Hat Security Response Team has rated this update as having moderatesecurity impact A Common Vulnerability Scoring ...
Synopsis Moderate: jasperreports-server-pro security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An updated jasperreports-server-pro package that fixes two security issues,several bugs, and adds various enhancements is now availableThe Red Hat Security Response Team has ...
Synopsis Moderate: axis security update Type/Severity Security Advisory: Moderate Topic Updated axis packages that fix one security issue are now available for RedHat Enterprise Linux 6The Red Hat Security Response Team has rated this update as having moderatesecurity impact A Common Vulnerability Scoring ...
Debian Bug report logs - #692650 axis: CVE-2012-5784 Package: axis; Maintainer for axis is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Thu, 8 Nov 2012 07:15:02 UTC Severity: grave Tags: patch, security Fixed in versions axis/14-162 ...
Debian Bug report logs - #692442 CVE-2012-5783: Insecure certificate validation Package: commons-httpclient; Maintainer for commons-httpclient is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Tue, 6 Nov 2012 11:00:01 UTC Severity: impor ...
Debian Bug report logs - #762444 Insecure certificate validation CVE-2014-3596 Package: axis; Maintainer for axis is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Raphael Hertzog <hertzog@debianorg> Date: Mon, 22 Sep 2014 12:03:02 UTC Severity: grave Tags: patch, security Fixe ...
Apache Axis did not verify that the server hostname matched the domain name in the subject's Common Name (CN) or subjectAltName field in X509 certificates This could allow a man-in-the-middle attacker to spoof an SSL server if they had a certificate that was valid for any domain name (CVE-2012-5784) ...