1 results (0.002 seconds)

CVSS: 5.9EPSS: 3%CPEs: 1EXPL: 0

29 Sep 2014 — Apache Axis2/C does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. Apache Axis2/C no verifica que el nombre del servidor coincide con un nombre de dominio en el campo del asunto Common Name (CN) o subjectAltName del certificado X.509, lo que permite a atacantes man-in-the-middle falsificar servidores SSL a través de u... • http://mail-archives.apache.org/mod_mbox/axis-c-dev/201301.mbox/browser • CWE-310: Cryptographic Issues •