Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 12

Количество 12

github логотип

GHSA-55w9-c3g2-4rrh

почти 6 лет назад

Man-in-the-middle attack in Apache Axis

EPSS: Низкий
ubuntu логотип

CVE-2012-5784

больше 13 лет назад

Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS2: 5.8
EPSS: Низкий
redhat логотип

CVE-2012-5784

почти 14 лет назад

Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-5784

больше 13 лет назад

Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2012-5784

больше 13 лет назад

Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Ma ...

CVSS2: 5.8
EPSS: Низкий
oracle-oval логотип

ELSA-2013-0683

больше 13 лет назад

ELSA-2013-0683: axis security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2013-0269

больше 13 лет назад

ELSA-2013-0269: axis security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:1526-1

около 7 лет назад

Security update for axis

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:1497-1

около 7 лет назад

Security update for axis

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1382-1

около 7 лет назад

Security update for axis

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1373-2

почти 7 лет назад

Security update for axis

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1373-1

около 7 лет назад

Security update for axis

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-55w9-c3g2-4rrh

Man-in-the-middle attack in Apache Axis

6%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2012-5784

Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS2: 5.8
6%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5784

Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS2: 4.3
6%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-5784

Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS2: 5.8
6%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-5784

Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Ma ...

CVSS2: 5.8
6%
Низкий
больше 13 лет назад
oracle-oval логотип
ELSA-2013-0683

ELSA-2013-0683: axis security update (MODERATE)

6%
Низкий
больше 13 лет назад
oracle-oval логотип
ELSA-2013-0269

ELSA-2013-0269: axis security update (MODERATE)

6%
Низкий
больше 13 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1526-1

Security update for axis

около 7 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1497-1

Security update for axis

около 7 лет назад
suse-cvrf логотип
SUSE-SU-2019:1382-1

Security update for axis

около 7 лет назад
suse-cvrf логотип
SUSE-SU-2019:1373-2

Security update for axis

почти 7 лет назад
suse-cvrf логотип
SUSE-SU-2019:1373-1

Security update for axis

около 7 лет назад

Уязвимостей на страницу