CVE Vulnerabilities

CVE-2012-5783

Improper Certificate Validation

Published: Nov 04, 2012 | Modified: Apr 23, 2021
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
3.7 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Ubuntu
LOW

Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subjects Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Httpclient Apache 3.1 (including) 3.1 (including)
JBEWP 5 for RHEL 5 RedHat jakarta-commons-httpclient-1:3.1-2.1_patch_01.ep5.el5 *
JBEWP 5 for RHEL 6 RedHat jakarta-commons-httpclient-1:3.1-2_patch_01.ep5.el6 *
JBoss Enterprise BRMS Platform 5.3 RedHat jakarta-commons-httpclient *
Red Hat Enterprise Linux 5 RedHat jakarta-commons-httpclient-1:3.0-7jpp.2 *
Red Hat Enterprise Linux 6 RedHat jakarta-commons-httpclient-1:3.1-0.7.el6_3 *
Red Hat Fuse 7.12 RedHat *
Red Hat JBoss A-MQ 6.3 RedHat *
Red Hat JBoss Enterprise Application Platform 5.2 RedHat *
Red Hat JBoss Enterprise Application Platform 5 for RHEL 4 RedHat jakarta-commons-httpclient-1:3.1-2.1_patch_01.ep5.el4 *
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 RedHat jakarta-commons-httpclient-1:3.1-2.1_patch_01.ep5.el5 *
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 RedHat jakarta-commons-httpclient-1:3.1-2_patch_01.ep5.el6 *
Red Hat JBoss Fuse 6.3 RedHat *
Red Hat JBoss Operations Network 3.2 RedHat *
Red Hat JBoss SOA Platform 5.3 RedHat jakarta-commons-httpclient *
Red Hat JBoss Web Framework Kit 2.2 RedHat jakarta-commons-httpclient *
Red Hat JBoss Web Platform 5.2 RedHat *
RHEV Manager version 3.3 RedHat redhat-support-plugin-rhev-0:3.3.0-14.el6ev *
Commons-httpclient Ubuntu hardy *
Commons-httpclient Ubuntu lucid *
Commons-httpclient Ubuntu oneiric *
Commons-httpclient Ubuntu precise *
Commons-httpclient Ubuntu quantal *
Commons-httpclient Ubuntu upstream *

Potential Mitigations

References