CVE-2012-5785
published 2012-11-04CVE-2012-5785: Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of…
PriorityP427medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
2.21%
80.5th percentile
Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | axis2 | <= 1.6.2 | — |
| apache | axis2 | — | — |
| apache | axis2 | — | — |
| apache | axis2 | — | — |
| apache | axis2 | — | — |
| apache | axis2 | — | — |
| apache | axis2 | — | — |
| apache | axis2 | — | — |
| apache | axis2 | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Axis2 has Improper Input Validation
osv·2022-05-17
CVE-2012-5785 [MEDIUM] Apache Axis2 has Improper Input Validation
Apache Axis2 has Improper Input Validation
Apache Axis2/Java 1.7.9 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
GHSA
Apache Axis2 has Improper Input Validation
ghsa·2022-05-17
CVE-2012-5785 [MEDIUM] CWE-20 Apache Axis2 has Improper Input Validation
Apache Axis2 has Improper Input Validation
Apache Axis2/Java 1.7.9 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Red Hat
axis2: Does not verify that the server hostname matches a domain name in the subject's CN or subjectAltName field of the x.509 certificate
vendor_redhat·2012-10-16·CVSS 5.8
CVE-2012-5785 [MEDIUM] axis2: Does not verify that the server hostname matches a domain name in the subject's CN or subjectAltName field of the x.509 certificate
axis2: Does not verify that the server hostname matches a domain name in the subject's CN or subjectAltName field of the x.509 certificate
Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Statement: Not vulnerable. This issue only affects axis2 as shipped with Fedora. It does not affect components shipped with any Red Hat products.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-5785 axis2: Does not verify that the server hostname matches a domain name in the subject's CN or subjectAltName field of the x.509 certificate [fedora-17]
bugzilla·2012-11-05·CVSS 5.8
CVE-2012-5785 [MEDIUM] CVE-2012-5785 axis2: Does not verify that the server hostname matches a domain name in the subject's CN or subjectAltName field of the x.509 certificate [fedora-17]
CVE-2012-5785 axis2: Does not verify that the server hostname matches a domain name in the subject's CN or subjectAltName field of the x.509 certificate [fedora-17]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in t
Bugzilla
CVE-2012-5785 axis2: Does not verify that the server hostname matches a domain name in the subject's CN or subjectAltName field of the x.509 certificate
bugzilla·2012-11-05·CVSS 5.8
CVE-2012-5785 [MEDIUM] CVE-2012-5785 axis2: Does not verify that the server hostname matches a domain name in the subject's CN or subjectAltName field of the x.509 certificate
CVE-2012-5785 axis2: Does not verify that the server hostname matches a domain name in the subject's CN or subjectAltName field of the x.509 certificate
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-5785 to the following vulnerability:
Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
References:
[1] http://www.cs.utexas.edu/~shmat/shmat_ccs12.pdf
[2] https://crypto.stanford.edu/~dabo/pubs/abstracts/ssl-client-bugs.html
[3] http://www.sigsac.org/ccs/CCS2012/techprogram.shtml
Discussion:
Created axis2 tracking bugs for this issue
Affec
http://secunia.com/advisories/51219http://www.cs.utexas.edu/~shmat/shmat_ccs12.pdfhttp://www.securityfocus.com/bid/56408https://exchange.xforce.ibmcloud.com/vulnerabilities/79830http://secunia.com/advisories/51219http://www.cs.utexas.edu/~shmat/shmat_ccs12.pdfhttp://www.securityfocus.com/bid/56408https://exchange.xforce.ibmcloud.com/vulnerabilities/79830
2012-11-04
Published