Логотип exploitDog
bind:CVE-2014-3603
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2014-3603

Количество 5

Количество 5

ubuntu логотип

CVE-2014-3603

почти 7 лет назад

The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 and OpenSAML Java 2.6.2 do not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2014-3603

больше 11 лет назад

The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 and OpenSAML Java 2.6.2 do not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2014-3603

почти 7 лет назад

The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 and OpenSAML Java 2.6.2 do not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2014-3603

почти 7 лет назад

The (1) HttpResource and (2) FileBackedHttpResource implementations in ...

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-rm7v-gqfg-p2wc

больше 3 лет назад

Improper Validation of Certificate with Host Mismatch in Shibboleth Identity Provider and OpenSAML Java

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2014-3603

The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 and OpenSAML Java 2.6.2 do not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS3: 5.9
0%
Низкий
почти 7 лет назад
redhat логотип
CVE-2014-3603

The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 and OpenSAML Java 2.6.2 do not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS2: 5.8
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-3603

The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 and OpenSAML Java 2.6.2 do not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS3: 5.9
0%
Низкий
почти 7 лет назад
debian логотип
CVE-2014-3603

The (1) HttpResource and (2) FileBackedHttpResource implementations in ...

CVSS3: 5.9
0%
Низкий
почти 7 лет назад
github логотип
GHSA-rm7v-gqfg-p2wc

Improper Validation of Certificate with Host Mismatch in Shibboleth Identity Provider and OpenSAML Java

CVSS3: 5.9
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу