Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2012-5783
Description:Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Test IDs: 1.3.6.1.4.1.25623.1.0.865298   1.3.6.1.4.1.25623.1.0.123724   1.3.6.1.4.1.25623.1.0.881604   1.3.6.1.4.1.25623.1.0.120384   1.3.6.1.4.1.25623.1.0.870917   1.3.6.1.4.1.25623.1.1.1.2.2015.222   1.3.6.1.4.1.25623.1.0.865277   1.3.6.1.4.1.25623.1.0.120079   1.3.6.1.4.1.25623.1.0.865280   1.3.6.1.4.1.25623.1.0.842488   1.3.6.1.4.1.25623.1.1.10.2013.0199   1.3.6.1.4.1.25623.1.1.4.2013.0610.1  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2012-5783
BugTraq ID: 58073
http://www.securityfocus.com/bid/58073
http://www.cs.utexas.edu/~shmat/shmat_ccs12.pdf
RedHat Security Advisories: RHSA-2013:0270
http://rhn.redhat.com/errata/RHSA-2013-0270.html
RedHat Security Advisories: RHSA-2013:0679
http://rhn.redhat.com/errata/RHSA-2013-0679.html
RedHat Security Advisories: RHSA-2013:0680
http://rhn.redhat.com/errata/RHSA-2013-0680.html
RedHat Security Advisories: RHSA-2013:0681
http://rhn.redhat.com/errata/RHSA-2013-0681.html
RedHat Security Advisories: RHSA-2013:0682
http://rhn.redhat.com/errata/RHSA-2013-0682.html
RedHat Security Advisories: RHSA-2013:1147
http://rhn.redhat.com/errata/RHSA-2013-1147.html
RedHat Security Advisories: RHSA-2013:1853
http://rhn.redhat.com/errata/RHSA-2013-1853.html
RedHat Security Advisories: RHSA-2014:0224
http://rhn.redhat.com/errata/RHSA-2014-0224.html
RedHat Security Advisories: RHSA-2017:0868
https://access.redhat.com/errata/RHSA-2017:0868
SuSE Security Announcement: openSUSE-SU-2013:0354 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-02/msg00078.html
SuSE Security Announcement: openSUSE-SU-2013:0622 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-04/msg00040.html
SuSE Security Announcement: openSUSE-SU-2013:0623 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-04/msg00041.html
SuSE Security Announcement: openSUSE-SU-2013:0638 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-04/msg00053.html
http://www.ubuntu.com/usn/USN-2769-1
XForce ISS Database: apache-commons-ssl-spoofing(79984)
https://exchange.xforce.ibmcloud.com/vulnerabilities/79984




© 1998-2025 E-Soft Inc. All rights reserved.