SSL Spoofing Vulnerability in Apache Axis Products
CVE-2012-5784

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
4 November 2012

What is CVE-2012-5784?

The vulnerability arises from Apache Axis and related products failing to ensure that the server hostname matches the domain specified in the X.509 certificate's Common Name (CN) or subjectAltName field. This oversight can be exploited by attackers to perform man-in-the-middle attacks, enabling them to impersonate legitimate SSL servers with valid certificates, consequently jeopardizing the integrity and confidentiality of sensitive data being transmitted.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.