5.8

CVE-2014-3596

The getCN function in Apache Axis 1.4 and earlier does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5784.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheAxis Version <= 1.4
ApacheAxis Version1.0
ApacheAxis Version1.0 Updatebeta
ApacheAxis Version1.0 Updaterc1
ApacheAxis Version1.0 Updaterc2
ApacheAxis Version1.1
ApacheAxis Version1.1 Updatebeta
ApacheAxis Version1.1 Updaterc1
ApacheAxis Version1.1 Updaterc2
ApacheAxis Version1.2
ApacheAxis Version1.2 Updatealpha
ApacheAxis Version1.2 Updatebeta1
ApacheAxis Version1.2 Updatebeta2
ApacheAxis Version1.2 Updatebeta3
ApacheAxis Version1.2 Updaterc1
ApacheAxis Version1.2 Updaterc2
ApacheAxis Version1.2 Updaterc3
ApacheAxis Version1.2.1
ApacheAxis Version1.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.18% 0.78
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N