Back

MEDIUM

axis: SSL hostname verification bypass, incomplete CVE-2012-5784 fix

Published Aug 27, 2014

Description

The getCN function in Apache Axis 1.4 and earlier does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5784.

Affected products

Remediation

Red Hat statement

Note that Axis 1 is EOL upstream, and the incomplete patch for CVE-2012-5784 was never merged upstream. It was, however, shipped by various vendors, including Debian and Red Hat. Additional information can be found in the Red Hat Knowledgebase article: https://access.redhat.com/solutions/1164433

Metrics

Weaknesses (1)

References (30)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 27, 2014
Updated Aug 6, 2024
Reserved May 14, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Aug 19, 2014
GHSA-R53V-VM87-F72C