CVE-2012-5817 Information
Feb 14, 2021
cve
Description
Codehaus XFire 1.2.6 and earlier as used in the Amazon EC2 API Tools Java library and other products does not verify that the server hostname matches a domain name in the subject’s Common Name (CN) or subjectAltName field of the X.509 certificate which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Reference
http://www.cs.utexas.edu/~shmat/shmat_ccs12.pdf https://exchange.xforce.ibmcloud.com/vulnerabilities/79934
Share on: