CVE Vulnerabilities

CVE-2012-5783

Improper Certificate Validation

Published: Nov 04, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
3.7 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subjects Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
HttpclientApache3.1 (including)3.1 (including)
JBEWP 5 for RHEL 5RedHatjakarta-commons-httpclient-1:3.1-2.1_patch_01.ep5.el5*
JBEWP 5 for RHEL 6RedHatjakarta-commons-httpclient-1:3.1-2_patch_01.ep5.el6*
JBoss Enterprise BRMS Platform 5.3RedHat*
Red Hat Enterprise Linux 5RedHatjakarta-commons-httpclient-1:3.0-7jpp.2*
Red Hat Enterprise Linux 6RedHatjakarta-commons-httpclient-1:3.1-0.7.el6_3*
Red Hat Fuse 7.12RedHat*
Red Hat JBoss A-MQ 6.3RedHat*
Red Hat JBoss Enterprise Application Platform 5.2RedHat*
Red Hat JBoss Enterprise Application Platform 5 for RHEL 4RedHatjakarta-commons-httpclient-1:3.1-2.1_patch_01.ep5.el4*
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5RedHatjakarta-commons-httpclient-1:3.1-2.1_patch_01.ep5.el5*
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6RedHatjakarta-commons-httpclient-1:3.1-2_patch_01.ep5.el6*
Red Hat JBoss Fuse 6.3RedHat*
Red Hat JBoss Operations Network 3.2RedHat*
Red Hat JBoss SOA Platform 5.3RedHat*
Red Hat JBoss Web Framework Kit 2.2RedHat*
Red Hat JBoss Web Platform 5.2RedHat*
RHEV Manager version 3.3RedHatredhat-support-plugin-rhev-0:3.3.0-14.el6ev*
Commons-httpclientUbuntuhardy*
Commons-httpclientUbuntulucid*
Commons-httpclientUbuntuoneiric*
Commons-httpclientUbuntuprecise*
Commons-httpclientUbuntuquantal*
Commons-httpclientUbuntuupstream*

Potential Mitigations

References