// For flags

CVE-2012-5784

axis: missing connection hostname check against X.509 certificate name

Severity Score

5.8
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Apache Axis v1.4 y versiones anteriores, tal y como se utiliza en los pagos de PayPal Pro, PPayPal Mass Pay, PayPal Transactional Information SOAP, la implementación de Java Message Service en Apache ActiveMQ, y otros productos, no comprueba si el nombre del servidor coincide con un nombre de dominio en el Nombre Común (CN) del sujeto o el campo subjectAltName del certificado X.509, lo que permite falsificar servidores SSL a atacantes "man-in-the-middle" mediante un certificado válido de su elección.

Apache Axis did not verify that the server host name matched the domain name in the subject's Common Name (CN) or subjectAltName field in X.509 certificates. This could allow a man-in-the-middle attacker to spoof an SSL server if they had a certificate that was valid for any domain name.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-11-04 CVE Reserved
  • 2012-11-04 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-06 CVE Updated
  • 2024-08-06 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-20: Improper Input Validation
CAPEC
References (16)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Apache
Search vendor "Apache"
Activemq
Search vendor "Apache" for product "Activemq"
<= 5.7.0
Search vendor "Apache" for product "Activemq" and version " <= 5.7.0"
-
Affected
Apache
Search vendor "Apache"
Axis
Search vendor "Apache" for product "Axis"
<= 1.4
Search vendor "Apache" for product "Axis" and version " <= 1.4"
-
Affected
Apache
Search vendor "Apache"
Axis
Search vendor "Apache" for product "Axis"
-alpha1
Affected
Apache
Search vendor "Apache"
Axis
Search vendor "Apache" for product "Axis"
-alpha2
Affected
Apache
Search vendor "Apache"
Axis
Search vendor "Apache" for product "Axis"
-alpha3
Affected
Apache
Search vendor "Apache"
Axis
Search vendor "Apache" for product "Axis"
-beta1
Affected
Apache
Search vendor "Apache"
Axis
Search vendor "Apache" for product "Axis"
-beta2
Affected
Apache
Search vendor "Apache"
Axis
Search vendor "Apache" for product "Axis"
-beta3
Affected
Apache
Search vendor "Apache"
Axis
Search vendor "Apache" for product "Axis"
1.0
Search vendor "Apache" for product "Axis" and version "1.0"
-
Affected
Apache
Search vendor "Apache"
Axis
Search vendor "Apache" for product "Axis"
1.0
Search vendor "Apache" for product "Axis" and version "1.0"
beta
Affected
Apache
Search vendor "Apache"
Axis
Search vendor "Apache" for product "Axis"
1.0
Search vendor "Apache" for product "Axis" and version "1.0"
rc1
Affected
Apache
Search vendor "Apache"
Axis
Search vendor "Apache" for product "Axis"
1.0
Search vendor "Apache" for product "Axis" and version "1.0"
rc2
Affected
Apache
Search vendor "Apache"
Axis
Search vendor "Apache" for product "Axis"
1.1
Search vendor "Apache" for product "Axis" and version "1.1"
-
Affected
Apache
Search vendor "Apache"
Axis
Search vendor "Apache" for product "Axis"
1.1
Search vendor "Apache" for product "Axis" and version "1.1"
beta
Affected
Apache
Search vendor "Apache"
Axis
Search vendor "Apache" for product "Axis"
1.1
Search vendor "Apache" for product "Axis" and version "1.1"
rc1
Affected
Apache
Search vendor "Apache"
Axis
Search vendor "Apache" for product "Axis"
1.1
Search vendor "Apache" for product "Axis" and version "1.1"
rc2
Affected
Apache
Search vendor "Apache"
Axis
Search vendor "Apache" for product "Axis"
1.2
Search vendor "Apache" for product "Axis" and version "1.2"
-
Affected
Apache
Search vendor "Apache"
Axis
Search vendor "Apache" for product "Axis"
1.2
Search vendor "Apache" for product "Axis" and version "1.2"
alpha
Affected
Apache
Search vendor "Apache"
Axis
Search vendor "Apache" for product "Axis"
1.2
Search vendor "Apache" for product "Axis" and version "1.2"
beta1
Affected
Apache
Search vendor "Apache"
Axis
Search vendor "Apache" for product "Axis"
1.2
Search vendor "Apache" for product "Axis" and version "1.2"
beta2
Affected
Apache
Search vendor "Apache"
Axis
Search vendor "Apache" for product "Axis"
1.2
Search vendor "Apache" for product "Axis" and version "1.2"
beta3
Affected
Apache
Search vendor "Apache"
Axis
Search vendor "Apache" for product "Axis"
1.2
Search vendor "Apache" for product "Axis" and version "1.2"
rc1
Affected
Apache
Search vendor "Apache"
Axis
Search vendor "Apache" for product "Axis"
1.2
Search vendor "Apache" for product "Axis" and version "1.2"
rc2
Affected
Apache
Search vendor "Apache"
Axis
Search vendor "Apache" for product "Axis"
1.2
Search vendor "Apache" for product "Axis" and version "1.2"
rc3
Affected
Apache
Search vendor "Apache"
Axis
Search vendor "Apache" for product "Axis"
1.2.1
Search vendor "Apache" for product "Axis" and version "1.2.1"
-
Affected
Apache
Search vendor "Apache"
Axis
Search vendor "Apache" for product "Axis"
1.3
Search vendor "Apache" for product "Axis" and version "1.3"
-
Affected
Paypal
Search vendor "Paypal"
Mass Pay
Search vendor "Paypal" for product "Mass Pay"
--
Affected
Paypal
Search vendor "Paypal"
Payments Pro
Search vendor "Paypal" for product "Payments Pro"
--
Affected
Paypal
Search vendor "Paypal"
Transactional Information Soap
Search vendor "Paypal" for product "Transactional Information Soap"
--
Affected