CVE-2012-5783

CVSS v2.0 5.8 (Medium)
58% Progress
EPSS 0.24 % (62th)
0.24% Progress
Affected Products 2
Advisories 11

Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Weaknesses
CWE-295
Improper Certificate Validation
Related CVEs
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2012-11-04 22:55:03
(12 years ago)
Updated Date
2021-04-23 17:28:08
(3 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Apache Httpclient 3.1 cpe:2.3:a:apache:httpclient:3.1

Configuration #2

    CPE23 From Up To
  Canonical Ubuntu Linux 12.04 cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-
  Canonical Ubuntu Linux 14.04 cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm
  Canonical Ubuntu Linux 15.04 cpe:2.3:o:canonical:ubuntu_linux:15.04
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...