CVE-2012-5783
Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509…
Does this matter?
Lower severity and a low EPSS score (9.25%). Track it; it rarely justifies an emergency change on its own.
Description
Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
- CVSS 2.0
- 5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
- EPSS
- 9.25% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295
- Affected
- apache/httpclient · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-updates/2013-02/msg00078.htmlBroken Link
- http://lists.opensuse.org/opensuse-updates/2013-04/msg00040.htmlBroken Link
- http://lists.opensuse.org/opensuse-updates/2013-04/msg00041.htmlBroken Link
- http://lists.opensuse.org/opensuse-updates/2013-04/msg00053.htmlBroken Link
- http://rhn.redhat.com/errata/RHSA-2013-0270.htmlBroken Link
- http://rhn.redhat.com/errata/RHSA-2013-0679.htmlBroken Link
- http://rhn.redhat.com/errata/RHSA-2013-0680.htmlBroken Link
- http://rhn.redhat.com/errata/RHSA-2013-0681.htmlBroken Link
- http://rhn.redhat.com/errata/RHSA-2013-0682.htmlBroken Link
- http://rhn.redhat.com/errata/RHSA-2013-1147.htmlBroken Link
- http://rhn.redhat.com/errata/RHSA-2013-1853.htmlBroken Link
- http://rhn.redhat.com/errata/RHSA-2014-0224.htmlBroken Link
- http://www.cs.utexas.edu/~shmat/shmat_ccs12.pdfTechnical Description, Third Party Advisory
- http://www.securityfocus.com/bid/58073Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2769-1Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:0868Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79984Third Party Advisory, VDB Entry
- https://issues.apache.org/jira/browse/HTTPCLIENT-1265Issue Tracking, Patch, Vendor Advisory
- http://lists.opensuse.org/opensuse-updates/2013-02/msg00078.htmlBroken Link
- http://lists.opensuse.org/opensuse-updates/2013-04/msg00040.htmlBroken Link
- http://lists.opensuse.org/opensuse-updates/2013-04/msg00041.htmlBroken Link
- http://lists.opensuse.org/opensuse-updates/2013-04/msg00053.htmlBroken Link
- http://rhn.redhat.com/errata/RHSA-2013-0270.htmlBroken Link
- http://rhn.redhat.com/errata/RHSA-2013-0679.htmlBroken Link
- http://rhn.redhat.com/errata/RHSA-2013-0680.htmlBroken Link
- http://rhn.redhat.com/errata/RHSA-2013-0681.htmlBroken Link
- http://rhn.redhat.com/errata/RHSA-2013-0682.htmlBroken Link
- http://rhn.redhat.com/errata/RHSA-2013-1147.htmlBroken Link
- http://rhn.redhat.com/errata/RHSA-2013-1853.htmlBroken Link
- http://rhn.redhat.com/errata/RHSA-2014-0224.htmlBroken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.