5.8
CVSSv2

CVE-2012-5785

Published: 04/11/2012 Updated: 29/08/2017
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

Apache Axis2/Java 1.6.2 and previous versions does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle malicious users to spoof SSL servers via an arbitrary valid certificate.

Vulnerable Product Search on Vulmon Subscribe to Product

apache axis2 1.6.1

apache axis2 1.5.6

apache axis2 1.5.3

apache axis2 1.5.2

apache axis2 1.5.1

apache axis2

apache axis2 1.6

apache axis2 1.5.5

apache axis2 1.5.4