Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2012-11-04T22:00:00

Updated: 2019-09-10T02:06:13

Reserved: 2012-11-04T00:00:00


Link: CVE-2012-5784

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2012-11-04T22:55:03.327

Modified: 2023-11-07T02:12:41.587


Link: CVE-2012-5784

JSON object: View

cve-icon Redhat Information

No data.

CWE