Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subjects Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
The product does not validate, or incorrectly validates, a certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Httpclient | Apache | 3.1 (including) | 3.1 (including) |
JBEWP 5 for RHEL 5 | RedHat | jakarta-commons-httpclient-1:3.1-2.1_patch_01.ep5.el5 | * |
JBEWP 5 for RHEL 6 | RedHat | jakarta-commons-httpclient-1:3.1-2_patch_01.ep5.el6 | * |
JBoss Enterprise BRMS Platform 5.3 | RedHat | jakarta-commons-httpclient | * |
Red Hat Enterprise Linux 5 | RedHat | jakarta-commons-httpclient-1:3.0-7jpp.2 | * |
Red Hat Enterprise Linux 6 | RedHat | jakarta-commons-httpclient-1:3.1-0.7.el6_3 | * |
Red Hat Fuse 7.12 | RedHat | * | |
Red Hat JBoss A-MQ 6.3 | RedHat | * | |
Red Hat JBoss Enterprise Application Platform 5.2 | RedHat | * | |
Red Hat JBoss Enterprise Application Platform 5 for RHEL 4 | RedHat | jakarta-commons-httpclient-1:3.1-2.1_patch_01.ep5.el4 | * |
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 | RedHat | jakarta-commons-httpclient-1:3.1-2.1_patch_01.ep5.el5 | * |
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 | RedHat | jakarta-commons-httpclient-1:3.1-2_patch_01.ep5.el6 | * |
Red Hat JBoss Fuse 6.3 | RedHat | * | |
Red Hat JBoss Operations Network 3.2 | RedHat | * | |
Red Hat JBoss SOA Platform 5.3 | RedHat | jakarta-commons-httpclient | * |
Red Hat JBoss Web Framework Kit 2.2 | RedHat | jakarta-commons-httpclient | * |
Red Hat JBoss Web Platform 5.2 | RedHat | * | |
RHEV Manager version 3.3 | RedHat | redhat-support-plugin-rhev-0:3.3.0-14.el6ev | * |
Commons-httpclient | Ubuntu | hardy | * |
Commons-httpclient | Ubuntu | lucid | * |
Commons-httpclient | Ubuntu | oneiric | * |
Commons-httpclient | Ubuntu | precise | * |
Commons-httpclient | Ubuntu | quantal | * |
Commons-httpclient | Ubuntu | upstream | * |