SSL Spoofing Vulnerability in Apache Axis2 by The Apache Software Foundation
CVE-2012-5785

Currently unrated

Key Information:

Vendor

Apache

Status
Vendor
CVE Published:
4 November 2012

What is CVE-2012-5785?

The Apache Axis2 software, specifically versions 1.6.2 and earlier, contains a security flaw where the server hostname is not verified against the domain name in the subject's Common Name (CN) or in the subjectAltName field of the X.509 certificate. This oversight allows attackers to execute man-in-the-middle attacks by spoofing SSL servers using arbitrary valid certificates, potentially leading to unauthorized access to sensitive information.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.