MEDIUM🇵🇱 Wersja polska

CVE-2012-5784

CVSS 5.8v2.0pub. 2012-11-04upd. 2026-04-29

Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS Vector
AV:N/AC:M/Au:N/C:P/I:P/A:N
  • Apache Activemq

    APP
    Apache
    ≤ 5.7.0
  • Apache Axis

    APP
    Apache
    1.01.11.21.2.11.3≤ 1.4
  • Paypal Mass Pay

    APP
    Paypal
    all versions
  • Paypal Payments Pro

    APP
    Paypal
    all versions
  • Paypal Transactional Information Soap

    APP
    Paypal
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-46604CRITICAL10.0⚠ KEVPL ✓same product

Apache ActiveMQ — RCE przez podatny marshaller protokołu OpenWire

CVE-2016-3088CRITICAL9.8⚠ KEVPL ✓same product

Apache ActiveMQ Fileserver — upload i zdalne wykonanie kodu przez HTTP PUT/MOVE

CVE-2023-40743CRITICAL9.8PL ✓same product

Apache Axis 1.x — SSRF/RCE przez niebezpieczne mechanizmy lookup w ServiceFactory

CVE-2020-11998CRITICAL9.8PL ✓same product

Apache ActiveMQ — RCE przez błędną konfigurację JMX RMIConnectorServer

CVE-2013-7285CRITICAL9.8PL ✓same product

XStream RCE – wykonanie dowolnych poleceń przy deserializacji XML/JSON