← Back

CVE-2012-5784

nvd nist
Published: Nov 4, 2012Modified: Apr 29, 2026

JSON object

Loading...
5.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:N
Exploitability: 8.6 / Impact: 4.9
Source: NVD

Description

Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Affected (29)

2 products
Activemq
Axis
3 products
Mass Pay
Payments Pro
Transactional Information Soap
Configuration A
29 vulnerable
Vulnerable SoftwareAffected Versions
Up to 5.7.0
Apache
Up to 1.4
All versions
All versions
All versions
All versions
All versions
All versions
Version 1.0
Version 1.0 beta
Version 1.0 rc1
Version 1.0 rc2
Version 1.1
Version 1.1 beta
Version 1.1 rc1
Version 1.1 rc2
Version 1.2.1
Version 1.2
Version 1.2 alpha
Version 1.2 beta1
Version 1.2 beta2
Version 1.2 beta3
Version 1.2 rc1
Version 1.2 rc2
Version 1.2 rc3
Version 1.3
All versions
All versions
All versions

References (28)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
ExploitTechnical Description
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitTechnical Description
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.