Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
CVSS Details
- CVSS 3.1 Base Score: 3.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade jakarta-commons-httpclient-manualUpgrade jakarta-commons-httpclientUpgrade jakarta-commons-httpclient-javadocUpgrade jakarta-commons-httpclient-demo | Dec 1, 2016 | Nov 4, 2012 |
| Debian | — | Upgrade commons-httpclient | Jul 30, 2024 | Nov 4, 2012 |
| Freebsd | — | Upgrade jakarta-commons-httpclientUpgrade apache-commons-httpclient | Jul 13, 2026 | Jul 10, 2026 |
| Ibm Aix | — | Apply the fix or workaround for commonshttp_advisory | Jul 27, 2023 | Nov 4, 2012 |
| Ibm Was | — | Upgrade to minimal fix pack levels as required by interim fixes and then apply latest Interim Fix. | Jun 28, 2018 | Nov 4, 2012 |
| Oracle_linux | — | Upgrade jakarta-commons-httpclient-javadocUpgrade jakarta-commons-httpclientUpgrade jakarta-commons-httpclient-demoUpgrade jakarta-commons-httpclient-manual | Oct 16, 2024 | Oct 16, 2012 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Oct 16, 2012 |
| Suse | — | Upgrade apache-commons-httpclient-javadocUpgrade apache-commons-httpclient-demoUpgrade jakarta-commons-httpclient3Upgrade apache-commons-httpclientUpgrade apache-commons-httpclient-manual | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libcommons-httpclient-java | Nov 8, 2024 | Nov 4, 2012 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Nov 4, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub