The getCN function in Apache Axis 1.4 and earlier does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5784.
CVSS Details
- CVSS 3.1 Base Score: 4.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade axis-javadocUpgrade axisUpgrade axis-manual | Dec 1, 2016 | Aug 26, 2014 |
| Debian | — | Upgrade axis | Jul 30, 2024 | Aug 27, 2014 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Nov 11, 2015 |
| Oracle_linux | — | Upgrade axis-manualUpgrade axisUpgrade axis-javadoc | Oct 16, 2024 | Aug 27, 2014 |
| Suse | — | Upgrade axisUpgrade axis-manual | May 30, 2019 | Aug 26, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub