Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2012-5785
Description:Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in- the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2012-5785
BugTraq ID: 56408
http://www.securityfocus.com/bid/56408
http://www.cs.utexas.edu/~shmat/shmat_ccs12.pdf
http://secunia.com/advisories/51219
XForce ISS Database: apache-axis2-ssl-spoofing(79830)
https://exchange.xforce.ibmcloud.com/vulnerabilities/79830




© 1998-2025 E-Soft Inc. All rights reserved.