Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2014-3596

The getCN function in Apache Axis 1.4 and earlier does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5784.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.012
EPSS Ranking 78.1%
CVSS Severity
CVSS v2 Score 5.8
References
Products affected by CVE-2014-3596
  • Apache » Axis » Version: N/A
    cpe:2.3:a:apache:axis:-
  • Apache » Axis » Version: 1.0
    cpe:2.3:a:apache:axis:1.0
  • Apache » Axis » Version: 1.1
    cpe:2.3:a:apache:axis:1.1
  • Apache » Axis » Version: 1.2
    cpe:2.3:a:apache:axis:1.2
  • Apache » Axis » Version: 1.2.1
    cpe:2.3:a:apache:axis:1.2.1
  • Apache » Axis » Version: 1.3
    cpe:2.3:a:apache:axis:1.3
  • Apache » Axis » Version: 1.4
    cpe:2.3:a:apache:axis:1.4


Contact Us

Shodan ® - All rights reserved