5.8

CVE-2012-5784

Exploit
Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Activemq Version <= 5.7.0
Apache ≫ Axis Version <= 1.4
Apache ≫ Axis Version - Update alpha1
Apache ≫ Axis Version - Update alpha2
Apache ≫ Axis Version - Update alpha3
Apache ≫ Axis Version - Update beta1
Apache ≫ Axis Version - Update beta2
Apache ≫ Axis Version - Update beta3
Apache ≫ Axis Version 1.0
Apache ≫ Axis Version 1.0 Update beta
Apache ≫ Axis Version 1.0 Update rc1
Apache ≫ Axis Version 1.0 Update rc2
Apache ≫ Axis Version 1.1
Apache ≫ Axis Version 1.1 Update beta
Apache ≫ Axis Version 1.1 Update rc1
Apache ≫ Axis Version 1.1 Update rc2
Apache ≫ Axis Version 1.2
Apache ≫ Axis Version 1.2 Update alpha
Apache ≫ Axis Version 1.2 Update beta1
Apache ≫ Axis Version 1.2 Update beta2
Apache ≫ Axis Version 1.2 Update beta3
Apache ≫ Axis Version 1.2 Update rc1
Apache ≫ Axis Version 1.2 Update rc2
Apache ≫ Axis Version 1.2 Update rc3
Apache ≫ Axis Version 1.2.1
Apache ≫ Axis Version 1.3
Paypal ≫ Mass Pay Version -
Paypal ≫ Payments Pro Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.72% 0.92
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.cs.utexas.edu/~shmat/shmat_ccs12.pdf
Exploit
Technical Description
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00007.html
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00022.html
http://rhn.redhat.com/errata/RHSA-2013-0269.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0683.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-0037.html
Third Party Advisory
http://secunia.com/advisories/51219
http://www.securityfocus.com/bid/56408
Third Party Advisory
VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/79829
https://lists.apache.org/thread.html/44d4e88a5fa8ae60deb752029afe9054da87c5f859caf296fcf585e5%40%3Cjava-dev.axis.apache.org%3E
https://lists.apache.org/thread.html/5e6c92145deddcecf70c3604041dcbd615efa2d37632fc2b9c367780%40%3Cjava-dev.axis.apache.org%3E
https://lists.apache.org/thread.html/8aa25c99eeb0693fc229ec87d1423b5ed5d58558618706d8aba1d832%40%3Cjava-dev.axis.apache.org%3E
https://lists.apache.org/thread.html/a308887782e05da7cf692e4851ae2bd429a038570cbf594e6631cc8d%40%3Cjava-dev.axis.apache.org%3E
https://lists.apache.org/thread.html/de2af12dcaba653d02b03235327ca4aa930401813a3cced8e151d29c%40%3Cjava-dev.axis.apache.org%3E