« Volver al listado

CVE-2012-5784

Estado: ModificadaMedia (5.8)—

Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-5784",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-11-04T22:55:03.327",
  "references": [
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00007.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00022.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2013-0269.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2013-0683.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2014-0037.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/51219",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.cs.utexas.edu/~shmat/shmat_ccs12.pdf",
      "tags": [
        "Exploit",
        "Technical Description"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/56408",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/79829",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://lists.apache.org/thread.html/44d4e88a5fa8ae60deb752029afe9054da87c5f859caf296fcf585e5%40%3Cjava-dev.axis.apache.org%3E",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://lists.apache.org/thread.html/5e6c92145deddcecf70c3604041dcbd615efa2d37632fc2b9c367780%40%3Cjava-dev.axis.apache.org%3E",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://lists.apache.org/thread.html/8aa25c99eeb0693fc229ec87d1423b5ed5d58558618706d8aba1d832%40%3Cjava-dev.axis.apache.org%3E",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://lists.apache.org/thread.html/a308887782e05da7cf692e4851ae2bd429a038570cbf594e6631cc8d%40%3Cjava-dev.axis.apache.org%3E",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://lists.apache.org/thread.html/de2af12dcaba653d02b03235327ca4aa930401813a3cced8e151d29c%40%3Cjava-dev.axis.apache.org%3E",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00007.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00022.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2013-0269.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2013-0683.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2014-0037.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/51219",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.cs.utexas.edu/~shmat/shmat_ccs12.pdf",
      "tags": [
        "Exploit",
        "Technical Description"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/56408",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/79829",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.apache.org/thread.html/44d4e88a5fa8ae60deb752029afe9054da87c5f859caf296fcf585e5%40%3Cjava-dev.axis.apache.org%3E",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.apache.org/thread.html/5e6c92145deddcecf70c3604041dcbd615efa2d37632fc2b9c367780%40%3Cjava-dev.axis.apache.org%3E",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.apache.org/thread.html/8aa25c99eeb0693fc229ec87d1423b5ed5d58558618706d8aba1d832%40%3Cjava-dev.axis.apache.org%3E",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.apache.org/thread.html/a308887782e05da7cf692e4851ae2bd429a038570cbf594e6631cc8d%40%3Cjava-dev.axis.apache.org%3E",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.apache.org/thread.html/de2af12dcaba653d02b03235327ca4aa930401813a3cced8e151d29c%40%3Cjava-dev.axis.apache.org%3E",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate."
    },
    {
      "lang": "es",
      "value": "Apache Axis v1.4 y versiones anteriores, tal y como se utiliza en los pagos de PayPal Pro, PPayPal Mass Pay, PayPal Transactional Information SOAP, la implementación de Java Message Service en Apache ActiveMQ, y otros productos, no comprueba si el nombre del servidor coincide con un nombre de dominio en el Nombre Común (CN) del sujeto o el campo subjectAltName del certificado X.509, lo que permite  falsificar servidores SSL a atacantes \"man-in-the-middle\" mediante un certificado válido de su elección."
    }
  ],
  "lastModified": "2026-06-16T23:47:19.857",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DA0C6D29-FFCF-4D59-A2D3-2C226F3F679A",
              "versionEndIncluding": "5.7.0"
            },
            {
              "criteria": "cpe:2.3:a:apache:axis:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "827FBA12-D294-4BE1-A40C-41F924CF0F4F",
              "versionEndIncluding": "1.4"
            },
            {
              "criteria": "cpe:2.3:a:apache:axis:-:alpha1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "22B54AB2-E980-4766-9DE1-EFCAF397DDE3"
            },
            {
              "criteria": "cpe:2.3:a:apache:axis:-:alpha2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "07741726-4545-4FE4-8B21-AE8EDF1D9F5E"
            },
            {
              "criteria": "cpe:2.3:a:apache:axis:-:alpha3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "42CBEBCD-1987-4BE8-A9FA-4E7DE686B9CC"
            },
            {
              "criteria": "cpe:2.3:a:apache:axis:-:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "45127BAA-4182-4088-86EF-1061FB53DAB0"
            },
            {
              "criteria": "cpe:2.3:a:apache:axis:-:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F4AA1D2C-84CE-4174-9689-03FBF1732B85"
            },
            {
              "criteria": "cpe:2.3:a:apache:axis:-:beta3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AA1CEBE5-144B-4A45-BE08-7D326291CF07"
            },
            {
              "criteria": "cpe:2.3:a:apache:axis:1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "73757AE0-90E2-4043-BCB3-4E4046966CDB"
            },
            {
              "criteria": "cpe:2.3:a:apache:axis:1.0:beta:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C174104D-8503-4980-A94E-BDBF0B93DCDA"
            },
            {
              "criteria": "cpe:2.3:a:apache:axis:1.0:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "87D85696-F3B1-464A-B128-6BC4B927CBFE"
            },
            {
              "criteria": "cpe:2.3:a:apache:axis:1.0:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F4B1A6AF-6A53-4366-8651-86A496038F68"
            },
            {
              "criteria": "cpe:2.3:a:apache:axis:1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8F72EF91-1228-4C74-9EBE-10C8CE0FB2F8"
            },
            {
              "criteria": "cpe:2.3:a:apache:axis:1.1:beta:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C65CCC42-5AC7-4DF6-9BEF-7408A1EE51EC"
            },
            {
              "criteria": "cpe:2.3:a:apache:axis:1.1:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9B2FB9F2-AC00-4E70-A87F-63EBB0A0EC0E"
            },
            {
              "criteria": "cpe:2.3:a:apache:axis:1.1:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "28740512-6B79-4497-8E47-DEF23CABDE07"
            },
            {
              "criteria": "cpe:2.3:a:apache:axis:1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0A28F00E-C3DE-4D21-9773-B57D297A639A"
            },
            {
              "criteria": "cpe:2.3:a:apache:axis:1.2:alpha:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "38BCCACB-2AB4-4A54-8112-C3B741F32D15"
            },
            {
              "criteria": "cpe:2.3:a:apache:axis:1.2:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AC2647DC-521E-46FF-BB91-6C6CB8A250A5"
            },
            {
              "criteria": "cpe:2.3:a:apache:axis:1.2:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FC9CEDDA-B2BD-40DE-9726-738D321E2AFB"
            },
            {
              "criteria": "cpe:2.3:a:apache:axis:1.2:beta3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "04FD771B-D047-48C3-8190-A1AF718C0940"
            },
            {
              "criteria": "cpe:2.3:a:apache:axis:1.2:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F31760CD-32DB-4414-99C0-9837CCC7B205"
            },
            {
              "criteria": "cpe:2.3:a:apache:axis:1.2:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4877D35D-57F6-4AAD-BCDA-F93CEAD82098"
            },
            {
              "criteria": "cpe:2.3:a:apache:axis:1.2:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "38F308E0-086B-41A2-9BCF-0DF095DB9D3C"
            },
            {
              "criteria": "cpe:2.3:a:apache:axis:1.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FD0F7632-377A-4C0C-9F5F-648F81BF5267"
            },
            {
              "criteria": "cpe:2.3:a:apache:axis:1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E4304E82-831C-4104-8D1E-18B72AFF1D23"
            },
            {
              "criteria": "cpe:2.3:a:paypal:mass_pay:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "92EA0D41-366C-4EEE-AB0F-6A5C93F4C97F"
            },
            {
              "criteria": "cpe:2.3:a:paypal:payments_pro:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2C8BF4D1-0D5B-4404-92DC-8147192503B7"
            },
            {
              "criteria": "cpe:2.3:a:paypal:transactional_information_soap:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C9ACE3D7-3DB1-4B23-810F-B47FF9199A2B"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}