First published: Sun Nov 04 2012(Updated: )
The CyberSource module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cybersource Module Project Cybersource | ||
Ubercart Ubercart |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-5804 is considered a medium severity vulnerability due to the risk of man-in-the-middle attacks.
To fix CVE-2012-5804, update the CyberSource module in Ubercart to a version that includes the hostname verification feature.
CVE-2012-5804 affects the CyberSource module of Ubercart.
CVE-2012-5804 can be exploited through man-in-the-middle attacks that allow SSL server spoofing.
CVE-2012-5804 can impact any installation of the affected versions of Ubercart using CyberSource for payment processing.