CXF: SSL hostname verification bypass, incomplete CVE-2012-6153 fix
Published Aug 21, 2014
4.8
MEDIUMCVSS 3.0
EPSS 9.15%
Description
org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "CN=" string in a field in the distinguished name (DN) of a certificate, as demonstrated by the "foo,CN=www.apache.org" string in the O field.
Affected products
No data.
Configuration 1
- ≥ 4.0 · ≤ 4.3.4
Configuration 2
- ≥ 4.0 · ≤ 4.0.1
No data.
JBEWP 5 for RHEL 5
apache-cxf-0:2.2.12-14.patch_09.ep5.el5
Fixed · RHSA-2014:1833
JBEWP 5 for RHEL 5
jakarta-commons-httpclient-1:3.1-4_patch_02.ep5.el5
Fixed · RHSA-2014:1320
JBEWP 5 for RHEL 5
jboss-seam2-0:2.2.6.EAP5-22_patch_01.ep5.el5
Fixed · RHSA-2014:1320
JBEWP 5 for RHEL 6
apache-cxf-0:2.2.12-14.patch_09.el6
Fixed · RHSA-2014:1833
JBEWP 5 for RHEL 6
jakarta-commons-httpclient-1:3.1-4_patch_02.el6_5
Fixed · RHSA-2014:1320
JBEWP 5 for RHEL 6
jboss-seam2-0:2.2.6.EAP5-22_patch_01.el6
Fixed · RHSA-2014:1320
RHEV Manager version 3.5
org.ovirt.engine-root-0:3.5.0-29
Fixed · RHSA-2015:0158
Red Hat Enterprise Linux 5
jakarta-commons-httpclient-1:3.0-7jpp.4.el5_10
Fixed · RHSA-2014:1166
Red Hat Enterprise Linux 6
jakarta-commons-httpclient-1:3.1-0.9.el6_5
Fixed · RHSA-2014:1166
Red Hat Enterprise Linux 7
httpcomponents-client-0:4.2.5-5.el7_0
Fixed · RHSA-2014:1146
Red Hat Enterprise Linux 7
jakarta-commons-httpclient-1:3.1-16.el7_0
Fixed · RHSA-2014:1166
Red Hat JBoss A-MQ 6.2
n/a
Fixed · RHSA-2016:1931
Red Hat JBoss A-MQ 6.2
n/a
Fixed · RHSA-2015:1177
Red Hat JBoss BPMS 6.0
cxf
Fixed · RHSA-2015:0851
Red Hat JBoss BPMS 6.0
httpclient
Fixed · RHSA-2015:0234
Red Hat JBoss BPMS 6.0
jakarta-commons-httpclient
Fixed · RHSA-2014:1892
Red Hat JBoss BPMS 6.0
jakarta-commons-httpclient
Fixed · RHSA-2015:0851
Red Hat JBoss BRMS 6.0
cxf
Fixed · RHSA-2015:0850
Red Hat JBoss BRMS 6.0
httpclient
Fixed · RHSA-2015:0235
Red Hat JBoss BRMS 6.0
jakarta-commons-httpclient
Fixed · RHSA-2014:1891
Red Hat JBoss BRMS 6.0
jakarta-commons-httpclient
Fixed · RHSA-2015:0850
Red Hat JBoss Data Virtualization 6.0
httpclient
Fixed · RHSA-2015:0765
Red Hat JBoss Data Virtualization 6.1
n/a
Fixed · RHSA-2015:0675
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5
apache-cxf-0:2.2.12-14.patch_09.ep5.el5
Fixed · RHSA-2014:1834
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5
jakarta-commons-httpclient-1:3.1-4_patch_02.ep5.el5
Fixed · RHSA-2014:1321
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5
jboss-seam2-0:2.2.6.EAP5-22_patch_01.ep5.el5
Fixed · RHSA-2014:1321
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6
apache-cxf-0:2.2.12-14.patch_09.el6
Fixed · RHSA-2014:1834
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6
jakarta-commons-httpclient-1:3.1-4_patch_02.el6_5
Fixed · RHSA-2014:1321
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6
jboss-seam2-0:2.2.6.EAP5-22_patch_01.el6
Fixed · RHSA-2014:1321
Red Hat JBoss Enterprise Application Platform 5.2
n/a
Fixed · RHSA-2014:1836
Red Hat JBoss Enterprise Application Platform 5.2
httpclient
Fixed · RHSA-2014:1323
Red Hat JBoss Enterprise Application Platform 5.2
jakarta-commons-httpclient
Fixed · RHSA-2014:1323
Red Hat JBoss Enterprise Application Platform 6.3
n/a
Fixed · RHSA-2014:2020
Red Hat JBoss Enterprise Application Platform 6.3
n/a
Fixed · RHSA-2014:1163
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5
apache-cxf-0:2.7.12-1.SP1_redhat_5.1.ep6.el5
Fixed · RHSA-2014:2019
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5
httpcomponents-eap6-0:6-12.redhat_2.1.ep6.el5
Fixed · RHSA-2014:1162
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5
wss4j-0:1.6.16-2.redhat_3.1.ep6.el5
Fixed · RHSA-2014:2019
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 6
apache-cxf-0:2.7.12-1.SP1_redhat_5.1.ep6.el6
Fixed · RHSA-2014:2019
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 6
httpcomponents-eap6-0:6-12.redhat_2.1.ep6.el6
Fixed · RHSA-2014:1162
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 6
wss4j-0:1.6.16-2.redhat_3.1.ep6.el6
Fixed · RHSA-2014:2019
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 7
apache-cxf-0:2.7.12-1.SP1_redhat_5.1.ep6.el7
Fixed · RHSA-2014:2019
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 7
httpcomponents-eap6-0:6-12.redhat_2.1.ep6.el7
Fixed · RHSA-2014:1162
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 7
wss4j-0:1.6.16-2.redhat_3.1.ep6.el7
Fixed · RHSA-2014:2019
Red Hat JBoss Fuse 6.2
n/a
Fixed · RHSA-2015:1176
Red Hat JBoss Fuse 6.2
n/a
Fixed · RHSA-2016:1931
Red Hat JBoss Fuse Service Works 6.0
httpclient
Fixed · RHSA-2015:0720
Red Hat JBoss Operations Network 3.3
httpclient
Fixed · RHSA-2014:1904
Red Hat JBoss Operations Network 3.3
jakarta-commons-httpclient
Fixed · RHSA-2014:1904
Red Hat JBoss Portal 6.2
httpclient
Fixed · RHSA-2015:1009
Red Hat JBoss SOA Platform 5.3
cxf
Fixed · RHSA-2015:1888
Red Hat JBoss SOA Platform 5.3
httpclient
Fixed · RHSA-2015:1888
Red Hat JBoss SOA Platform 5.3
jakarta-commons-httpclient
Fixed · RHSA-2015:1888
Red Hat JBoss Web Framework Kit 2.7
httpclient
Fixed · RHSA-2015:0125
Red Hat JBoss Web Platform 5.2
n/a
Fixed · RHSA-2014:1835
Red Hat JBoss Web Platform 5.2
httpclient
Fixed · RHSA-2014:1322
Red Hat JBoss Web Platform 5.2
jakarta-commons-httpclient
Fixed · RHSA-2014:1322
Red Hat OpenShift Container Platform 4.10
jenkins-0:2.319.2.1643288987-1.el8
Fixed · RHSA-2022:0055
Red Hat OpenShift Enterprise 2.2
ImageMagick-0:6.7.2.7-5.el6_8
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
activemq-0:5.9.0-6.redhat.611463.el6op
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
jenkins-0:1.651.2-1.el6op
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
libcgroup-0:0.40.rc1-18.el6_8
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
openshift-origin-broker-0:1.16.3.2-1.el6op
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
openshift-origin-broker-util-0:1.37.6.2-1.el6op
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
openshift-origin-cartridge-cron-0:1.25.4.2-1.el6op
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
openshift-origin-cartridge-diy-0:1.26.2.2-1.el6op
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
openshift-origin-cartridge-haproxy-0:1.31.6.2-1.el6op
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
openshift-origin-cartridge-jbosseap-0:2.27.4.2-1.el6op
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
openshift-origin-cartridge-jbossews-0:1.35.5.2-1.el6op
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
openshift-origin-cartridge-jenkins-0:1.29.2.2-1.el6op
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
openshift-origin-cartridge-jenkins-client-0:1.26.1.1-1.el6op
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
openshift-origin-cartridge-mongodb-0:1.26.2.2-1.el6op
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
openshift-origin-cartridge-mysql-0:1.31.3.3-1.el6op
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
openshift-origin-cartridge-nodejs-0:1.33.1.2-1.el6op
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
openshift-origin-cartridge-perl-0:1.30.2.2-1.el6op
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
openshift-origin-cartridge-php-0:1.35.4.2-1.el6op
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
openshift-origin-cartridge-python-0:1.34.3.2-1.el6op
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
openshift-origin-cartridge-ruby-0:1.32.2.2-1.el6op
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
openshift-origin-msg-node-mcollective-0:1.30.2.2-1.el6op
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
openshift-origin-node-proxy-0:1.26.3.1-1.el6op
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
openshift-origin-node-util-0:1.38.7.1-1.el6op
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
rhc-0:1.38.7.1-1.el6op
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
rubygem-openshift-origin-admin-console-0:1.28.2.1-1.el6op
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
rubygem-openshift-origin-controller-0:1.38.6.4-1.el6op
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
rubygem-openshift-origin-frontend-haproxy-sni-proxy-0:0.5.2.1-1.el6op
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
rubygem-openshift-origin-msg-broker-mcollective-0:1.36.2.4-1.el6op
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
rubygem-openshift-origin-node-0:1.38.6.4-1.el6op
Fixed · RHSA-2016:1773
Red Hat OpenShift Enterprise 2.2
rubygem-openshift-origin-routing-daemon-0:0.26.6.1-1.el6op
Fixed · RHSA-2016:1773
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6
thermostat1-httpcomponents-client-0:4.2.5-3.4.el6.1
Fixed · RHSA-2014:1082
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUS
thermostat1-httpcomponents-client-0:4.2.5-3.4.el6.1
Fixed · RHSA-2014:1082
OpenShift Enterprise 1
jakarta-commons-httpclient
Will not fix
OpenShift Enterprise 1
wagon-http
Not affected
Red Hat Enterprise Virtualization 3
redhat-support-plugin-rhev
Affected
Red Hat Enterprise Virtualization 3
rhevm-dependencies
Affected
Red Hat JBoss BRMS 5
cxf
Affected
Red Hat JBoss BRMS 5
httpclient
Will not fix
Red Hat JBoss BRMS 5
jakarta-commons-httpclient
Will not fix
Red Hat JBoss BRMS 5
modeshape-client
Will not fix
Red Hat JBoss Data Grid 6
cxf
Affected
Red Hat JBoss Data Grid 6
httpclient
Affected
Red Hat JBoss Data Virtualization 6
cxf
Affected
Red Hat JBoss Data Virtualization 6
modeshape-client
Fix deferred
Red Hat JBoss Enterprise Application Platform 4
jakarta-commons-httpclient
Will not fix
Red Hat JBoss Enterprise Application Platform 5
cxf
Affected
Red Hat JBoss Enterprise Application Platform 6
cxf
Affected
Red Hat JBoss Enterprise Application Platform 6
jakarta-commons-httpclient
Fix deferred
Red Hat JBoss Enterprise Web Server 1
jakarta-commons-httpclient
Will not fix
Red Hat JBoss Fuse Service Works 6
cxf
Affected
Red Hat JBoss Operations Network 3
cxf
Affected
Red Hat JBoss Portal 5
httpclient
Affected
Red Hat JBoss Portal 5
jakarta-commons-httpclient
Affected
Red Hat JBoss Portal 6
cxf
Affected
Red Hat JBoss SOA Platform 4
jakarta-commons-httpclient
Will not fix
Red Hat OpenShift Enterprise 2
httpclient
Affected
Red Hat OpenShift Enterprise 2
wagon-http
Not affected
Red Hat Satellite 5
jakarta-commons-httpclient
Will not fix
Red Hat Satellite 6
httpcomponents-client
Affected
Red Hat Software Collections
maven30-httpcomponents-client
Affected
Red Hat Software Collections
maven30-jakarta-commons-httpclient
Affected
Red Hat Storage 2
rhevm-dependencies
Will not fix
Red Hat Storage 3
rhevm-dependencies
Will not fix
Red Hat Virtualization 4
ovirt-engine-sdk-java
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| JBEWP 5 for RHEL 5 | apache-cxf-0:2.2.12-14.patch_09.ep5.el5 | Fixed | RHSA-2014:1833 |
| JBEWP 5 for RHEL 5 | jakarta-commons-httpclient-1:3.1-4_patch_02.ep5.el5 | Fixed | RHSA-2014:1320 |
| JBEWP 5 for RHEL 5 | jboss-seam2-0:2.2.6.EAP5-22_patch_01.ep5.el5 | Fixed | RHSA-2014:1320 |
| JBEWP 5 for RHEL 6 | apache-cxf-0:2.2.12-14.patch_09.el6 | Fixed | RHSA-2014:1833 |
| JBEWP 5 for RHEL 6 | jakarta-commons-httpclient-1:3.1-4_patch_02.el6_5 | Fixed | RHSA-2014:1320 |
| JBEWP 5 for RHEL 6 | jboss-seam2-0:2.2.6.EAP5-22_patch_01.el6 | Fixed | RHSA-2014:1320 |
| RHEV Manager version 3.5 | org.ovirt.engine-root-0:3.5.0-29 | Fixed | RHSA-2015:0158 |
| Red Hat Enterprise Linux 5 | jakarta-commons-httpclient-1:3.0-7jpp.4.el5_10 | Fixed | RHSA-2014:1166 |
| Red Hat Enterprise Linux 6 | jakarta-commons-httpclient-1:3.1-0.9.el6_5 | Fixed | RHSA-2014:1166 |
| Red Hat Enterprise Linux 7 | httpcomponents-client-0:4.2.5-5.el7_0 | Fixed | RHSA-2014:1146 |
| Red Hat Enterprise Linux 7 | jakarta-commons-httpclient-1:3.1-16.el7_0 | Fixed | RHSA-2014:1166 |
| Red Hat JBoss A-MQ 6.2 | n/a | Fixed | RHSA-2016:1931 |
| Red Hat JBoss A-MQ 6.2 | n/a | Fixed | RHSA-2015:1177 |
| Red Hat JBoss BPMS 6.0 | cxf | Fixed | RHSA-2015:0851 |
| Red Hat JBoss BPMS 6.0 | httpclient | Fixed | RHSA-2015:0234 |
| Red Hat JBoss BPMS 6.0 | jakarta-commons-httpclient | Fixed | RHSA-2014:1892 |
| Red Hat JBoss BPMS 6.0 | jakarta-commons-httpclient | Fixed | RHSA-2015:0851 |
| Red Hat JBoss BRMS 6.0 | cxf | Fixed | RHSA-2015:0850 |
| Red Hat JBoss BRMS 6.0 | httpclient | Fixed | RHSA-2015:0235 |
| Red Hat JBoss BRMS 6.0 | jakarta-commons-httpclient | Fixed | RHSA-2014:1891 |
| Red Hat JBoss BRMS 6.0 | jakarta-commons-httpclient | Fixed | RHSA-2015:0850 |
| Red Hat JBoss Data Virtualization 6.0 | httpclient | Fixed | RHSA-2015:0765 |
| Red Hat JBoss Data Virtualization 6.1 | n/a | Fixed | RHSA-2015:0675 |
| Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 | apache-cxf-0:2.2.12-14.patch_09.ep5.el5 | Fixed | RHSA-2014:1834 |
| Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 | jakarta-commons-httpclient-1:3.1-4_patch_02.ep5.el5 | Fixed | RHSA-2014:1321 |
| Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 | jboss-seam2-0:2.2.6.EAP5-22_patch_01.ep5.el5 | Fixed | RHSA-2014:1321 |
| Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 | apache-cxf-0:2.2.12-14.patch_09.el6 | Fixed | RHSA-2014:1834 |
| Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 | jakarta-commons-httpclient-1:3.1-4_patch_02.el6_5 | Fixed | RHSA-2014:1321 |
| Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 | jboss-seam2-0:2.2.6.EAP5-22_patch_01.el6 | Fixed | RHSA-2014:1321 |
| Red Hat JBoss Enterprise Application Platform 5.2 | n/a | Fixed | RHSA-2014:1836 |
| Red Hat JBoss Enterprise Application Platform 5.2 | httpclient | Fixed | RHSA-2014:1323 |
| Red Hat JBoss Enterprise Application Platform 5.2 | jakarta-commons-httpclient | Fixed | RHSA-2014:1323 |
| Red Hat JBoss Enterprise Application Platform 6.3 | n/a | Fixed | RHSA-2014:2020 |
| Red Hat JBoss Enterprise Application Platform 6.3 | n/a | Fixed | RHSA-2014:1163 |
| Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5 | apache-cxf-0:2.7.12-1.SP1_redhat_5.1.ep6.el5 | Fixed | RHSA-2014:2019 |
| Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5 | httpcomponents-eap6-0:6-12.redhat_2.1.ep6.el5 | Fixed | RHSA-2014:1162 |
| Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5 | wss4j-0:1.6.16-2.redhat_3.1.ep6.el5 | Fixed | RHSA-2014:2019 |
| Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 6 | apache-cxf-0:2.7.12-1.SP1_redhat_5.1.ep6.el6 | Fixed | RHSA-2014:2019 |
| Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 6 | httpcomponents-eap6-0:6-12.redhat_2.1.ep6.el6 | Fixed | RHSA-2014:1162 |
| Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 6 | wss4j-0:1.6.16-2.redhat_3.1.ep6.el6 | Fixed | RHSA-2014:2019 |
| Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 7 | apache-cxf-0:2.7.12-1.SP1_redhat_5.1.ep6.el7 | Fixed | RHSA-2014:2019 |
| Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 7 | httpcomponents-eap6-0:6-12.redhat_2.1.ep6.el7 | Fixed | RHSA-2014:1162 |
| Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 7 | wss4j-0:1.6.16-2.redhat_3.1.ep6.el7 | Fixed | RHSA-2014:2019 |
| Red Hat JBoss Fuse 6.2 | n/a | Fixed | RHSA-2015:1176 |
| Red Hat JBoss Fuse 6.2 | n/a | Fixed | RHSA-2016:1931 |
| Red Hat JBoss Fuse Service Works 6.0 | httpclient | Fixed | RHSA-2015:0720 |
| Red Hat JBoss Operations Network 3.3 | httpclient | Fixed | RHSA-2014:1904 |
| Red Hat JBoss Operations Network 3.3 | jakarta-commons-httpclient | Fixed | RHSA-2014:1904 |
| Red Hat JBoss Portal 6.2 | httpclient | Fixed | RHSA-2015:1009 |
| Red Hat JBoss SOA Platform 5.3 | cxf | Fixed | RHSA-2015:1888 |
| Red Hat JBoss SOA Platform 5.3 | httpclient | Fixed | RHSA-2015:1888 |
| Red Hat JBoss SOA Platform 5.3 | jakarta-commons-httpclient | Fixed | RHSA-2015:1888 |
| Red Hat JBoss Web Framework Kit 2.7 | httpclient | Fixed | RHSA-2015:0125 |
| Red Hat JBoss Web Platform 5.2 | n/a | Fixed | RHSA-2014:1835 |
| Red Hat JBoss Web Platform 5.2 | httpclient | Fixed | RHSA-2014:1322 |
| Red Hat JBoss Web Platform 5.2 | jakarta-commons-httpclient | Fixed | RHSA-2014:1322 |
| Red Hat OpenShift Container Platform 4.10 | jenkins-0:2.319.2.1643288987-1.el8 | Fixed | RHSA-2022:0055 |
| Red Hat OpenShift Enterprise 2.2 | ImageMagick-0:6.7.2.7-5.el6_8 | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | activemq-0:5.9.0-6.redhat.611463.el6op | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | jenkins-0:1.651.2-1.el6op | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | libcgroup-0:0.40.rc1-18.el6_8 | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | openshift-origin-broker-0:1.16.3.2-1.el6op | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | openshift-origin-broker-util-0:1.37.6.2-1.el6op | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | openshift-origin-cartridge-cron-0:1.25.4.2-1.el6op | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | openshift-origin-cartridge-diy-0:1.26.2.2-1.el6op | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | openshift-origin-cartridge-haproxy-0:1.31.6.2-1.el6op | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | openshift-origin-cartridge-jbosseap-0:2.27.4.2-1.el6op | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | openshift-origin-cartridge-jbossews-0:1.35.5.2-1.el6op | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | openshift-origin-cartridge-jenkins-0:1.29.2.2-1.el6op | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | openshift-origin-cartridge-jenkins-client-0:1.26.1.1-1.el6op | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | openshift-origin-cartridge-mongodb-0:1.26.2.2-1.el6op | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | openshift-origin-cartridge-mysql-0:1.31.3.3-1.el6op | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | openshift-origin-cartridge-nodejs-0:1.33.1.2-1.el6op | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | openshift-origin-cartridge-perl-0:1.30.2.2-1.el6op | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | openshift-origin-cartridge-php-0:1.35.4.2-1.el6op | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | openshift-origin-cartridge-python-0:1.34.3.2-1.el6op | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | openshift-origin-cartridge-ruby-0:1.32.2.2-1.el6op | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | openshift-origin-msg-node-mcollective-0:1.30.2.2-1.el6op | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | openshift-origin-node-proxy-0:1.26.3.1-1.el6op | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | openshift-origin-node-util-0:1.38.7.1-1.el6op | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | rhc-0:1.38.7.1-1.el6op | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | rubygem-openshift-origin-admin-console-0:1.28.2.1-1.el6op | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | rubygem-openshift-origin-controller-0:1.38.6.4-1.el6op | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | rubygem-openshift-origin-frontend-haproxy-sni-proxy-0:0.5.2.1-1.el6op | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | rubygem-openshift-origin-msg-broker-mcollective-0:1.36.2.4-1.el6op | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | rubygem-openshift-origin-node-0:1.38.6.4-1.el6op | Fixed | RHSA-2016:1773 |
| Red Hat OpenShift Enterprise 2.2 | rubygem-openshift-origin-routing-daemon-0:0.26.6.1-1.el6op | Fixed | RHSA-2016:1773 |
| Red Hat Software Collections 1 for Red Hat Enterprise Linux 6 | thermostat1-httpcomponents-client-0:4.2.5-3.4.el6.1 | Fixed | RHSA-2014:1082 |
| Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUS | thermostat1-httpcomponents-client-0:4.2.5-3.4.el6.1 | Fixed | RHSA-2014:1082 |
| OpenShift Enterprise 1 | jakarta-commons-httpclient | Will not fix | n/a |
| OpenShift Enterprise 1 | wagon-http | Not affected | n/a |
| Red Hat Enterprise Virtualization 3 | redhat-support-plugin-rhev | Affected | n/a |
| Red Hat Enterprise Virtualization 3 | rhevm-dependencies | Affected | n/a |
| Red Hat JBoss BRMS 5 | cxf | Affected | n/a |
| Red Hat JBoss BRMS 5 | httpclient | Will not fix | n/a |
| Red Hat JBoss BRMS 5 | jakarta-commons-httpclient | Will not fix | n/a |
| Red Hat JBoss BRMS 5 | modeshape-client | Will not fix | n/a |
| Red Hat JBoss Data Grid 6 | cxf | Affected | n/a |
| Red Hat JBoss Data Grid 6 | httpclient | Affected | n/a |
| Red Hat JBoss Data Virtualization 6 | cxf | Affected | n/a |
| Red Hat JBoss Data Virtualization 6 | modeshape-client | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform 4 | jakarta-commons-httpclient | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 5 | cxf | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | cxf | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | jakarta-commons-httpclient | Fix deferred | n/a |
| Red Hat JBoss Enterprise Web Server 1 | jakarta-commons-httpclient | Will not fix | n/a |
| Red Hat JBoss Fuse Service Works 6 | cxf | Affected | n/a |
| Red Hat JBoss Operations Network 3 | cxf | Affected | n/a |
| Red Hat JBoss Portal 5 | httpclient | Affected | n/a |
| Red Hat JBoss Portal 5 | jakarta-commons-httpclient | Affected | n/a |
| Red Hat JBoss Portal 6 | cxf | Affected | n/a |
| Red Hat JBoss SOA Platform 4 | jakarta-commons-httpclient | Will not fix | n/a |
| Red Hat OpenShift Enterprise 2 | httpclient | Affected | n/a |
| Red Hat OpenShift Enterprise 2 | wagon-http | Not affected | n/a |
| Red Hat Satellite 5 | jakarta-commons-httpclient | Will not fix | n/a |
| Red Hat Satellite 6 | httpcomponents-client | Affected | n/a |
| Red Hat Software Collections | maven30-httpcomponents-client | Affected | n/a |
| Red Hat Software Collections | maven30-jakarta-commons-httpclient | Affected | n/a |
| Red Hat Storage 2 | rhevm-dependencies | Will not fix | n/a |
| Red Hat Storage 3 | rhevm-dependencies | Will not fix | n/a |
| Red Hat Virtualization 4 | ovirt-engine-sdk-java | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Additional information can be found in the Red Hat Knowledgebase article: https://access.redhat.com/solutions/1165533 This issue affects the versions of HttpComponents Client as shipped with Red Hat JBoss Data Grid 6 and Red Hat JBoss Data Virtualization 6; and ModeShape Client as shipped with Red Hat JBoss Data Virtualization 6. However, this flaw is not known to be exploitable under any supported scenario in Red Hat JBoss Data Grid 6 and JBoss Data Virtualization 6. A future update may address this issue. Red Hat JBoss Enterprise Application Platform 4, Red Hat JBoss SOA Platform 4, and Red Hat JBoss Web Server 1 are now in Phase 3, Extended Life Support, of their respective life cycles. This issue has been rated as having Important security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat JBoss Middleware and Red Hat JBoss Operations Network Product Update and Support Policy: https://access.redhat.com/support/policy/updates/jboss_notes/ Fuse ESB 4, Fuse Message Broker 5.2, 5.3, 5.4 and Fuse Services Framework 2.3, 2.4 are now in a reduced support phase receiving only Critical impact security fixes. This issue has been rated as having Important security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Fuse Product Life Cycle: https://access.redhat.com/support/policy/updates/fusesource/
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
AV:N/AC:M/Au:N/C:P/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (24 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 9.15% (0.09149) | 95.18th | v5 (v2026.06.15) |
| Jun 15, 2026 | 9.15% (0.09149) | 94.65th | v5 (v2026.06.15) |
| Mar 28, 2026 | 1.37% (0.01368) | 80.14th | v4 (v2025.03.14) |
| Mar 4, 2026 | 2.40% (0.02398) | 84.78th | v4 (v2025.03.14) |
| Mar 1, 2026 | 0.91% (0.00906) | 75.55th | v4 (v2025.03.14) |
| Feb 14, 2026 | 2.40% (0.02398) | 84.73th | v4 (v2025.03.14) |
| Mar 30, 2025 | 1.20% (0.01204) | 77.06th | v4 (v2025.03.14) |
| Mar 29, 2025 | 3.96% (0.03955) | 80.30th | v4 (v2025.03.14) |
| Mar 28, 2025 | 1.20% (0.01204) | 77.06th | v4 (v2025.03.14) |
| Mar 27, 2025 | 3.96% (0.03955) | 86.83th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.44% (0.00442) | 61.16th | v4 (v2025.03.14) |
| Dec 17, 2024 | 1.52% (0.01521) | 86.69th | v3 (v2023.03.01) |
| Dec 12, 2024 | 0.38% (0.00378) | 73.72th | v3 (v2023.03.01) |
| Apr 2, 2024 | 0.44% (0.00436) | 74.27th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.40% (0.00401) | 72.94th | v3 (v2023.03.01) |
| Oct 28, 2023 | 0.40% (0.00401) | 70.73th | v3 (v2023.03.01) |
| Sep 15, 2023 | 0.21% (0.00215) | 59.01th | v3 (v2023.03.01) |
| Jul 15, 2023 | 0.22% (0.00225) | 59.80th | v3 (v2023.03.01) |
| Jun 11, 2023 | 0.28% (0.00276) | 63.58th | v3 (v2023.03.01) |
| May 8, 2023 | 0.39% (0.00392) | 69.34th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.32% (0.00320) | 65.83th | v3 (v2023.03.01) |
| Mar 6, 2023 | 5.24% (0.05242) | 89.75th | v2 (v2022.01.01) |
| Apr 1, 2022 | 5.24% (0.05242) | 88.72th | v2 (v2022.01.01) |
| Feb 4, 2022 | 5.24% (0.05242) | 75.28th | v2 (v2022.01.01) |
References (63)
- http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00032.html vendor-advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00033.html vendor-advisory
- http://packetstormsecurity.com/files/127913/Apache-HttpComponents-Man-In-The-Middle.html ExploitThird Party AdvisoryVDB Entry
- http://rhn.redhat.com/errata/RHSA-2014-1146.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1166.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1833.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1834.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1835.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1836.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1891.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1892.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0125.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0158.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0675.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0720.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0765.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0850.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0851.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1176.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1177.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1888.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1773.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1931.html vendor-advisoryThird Party Advisory
- http://seclists.org/fulldisclosure/2014/Aug/48 mailing-listExploitMailing ListThird Party Advisory
- http://secunia.com/advisories/60466 third-party-advisoryThird Party Advisory
- http://secunia.com/advisories/60589 third-party-advisoryThird Party Advisory
- http://secunia.com/advisories/60713 third-party-advisoryThird Party Advisory
- http://www.openwall.com/lists/oss-security/2021/10/06/1 mailing-list
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.osvdb.org/110143 vdb-entryBroken Link
- http://www.securityfocus.com/bid/69258 vdb-entryThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1030812 vdb-entryThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-2769-1 vendor-advisoryThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2014-3577 Vendor Advisory
- https://access.redhat.com/solutions/1165533 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1129074 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95327 vdb-entryThird Party AdvisoryVDB Entry
- https://github.com/advisories/GHSA-cfh5-3ghh-wfjx Advisory
- https://github.com/apache/httpcomponents-client/commit/51cc67567765d67f878f0dcef61b5ded454d3122
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05103564 Third Party Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05363782 Third Party Advisory
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E
- https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4@%3Ccommits.cxf.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2014-3577
- https://security.netapp.com/advisory/ntap-20231027-0003
- https://svn.apache.org/viewvc?view=revision&revision=1614064
- https://www.cve.org/CVERecord?id=CVE-2014-3577
Change history (0)
No recorded changes yet.