Vulnerability Description
Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Activemq | <= 5.7.0 |
| Apache | Axis | <= 1.4 |
| Paypal | Mass Pay | - |
| Paypal | Payments Pro | - |
| Paypal | Transactional Information Soap | - |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00007.html
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00022.html
- http://rhn.redhat.com/errata/RHSA-2013-0269.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0683.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0037.htmlThird Party Advisory
- http://secunia.com/advisories/51219
- http://www.cs.utexas.edu/~shmat/shmat_ccs12.pdfExploitTechnical Description
- http://www.securityfocus.com/bid/56408Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79829
- https://lists.apache.org/thread.html/44d4e88a5fa8ae60deb752029afe9054da87c5f859c
- https://lists.apache.org/thread.html/5e6c92145deddcecf70c3604041dcbd615efa2d3763
- https://lists.apache.org/thread.html/8aa25c99eeb0693fc229ec87d1423b5ed5d58558618
- https://lists.apache.org/thread.html/a308887782e05da7cf692e4851ae2bd429a038570cb
- https://lists.apache.org/thread.html/de2af12dcaba653d02b03235327ca4aa930401813a3
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00007.html
FAQ
What is CVE-2012-5784?
CVE-2012-5784 is a vulnerability with a CVSS score of 5.8 (MEDIUM). Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, doe...
How severe is CVE-2012-5784?
CVE-2012-5784 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-5784?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Activemq, Apache Axis, Paypal Mass Pay, Paypal Payments Pro, Paypal Transactional Information Soap.