First published: Thu Aug 14 2014(Updated: )
Apache Axis and Axis2 could allow a remote attacker to conduct spoofing attacks, caused by and incomplete fix related to the failure to verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate. By persuading a victim to visit a Web site containing a specially-crafted certificate, an attacker could exploit this vulnerability using man-in-the-middle techniques to spoof an SSL server.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Axis | <=1.4 | |
Apache Axis | =1.0 | |
Apache Axis | =1.0-beta | |
Apache Axis | =1.0-rc1 | |
Apache Axis | =1.0-rc2 | |
Apache Axis | =1.1 | |
Apache Axis | =1.1-beta | |
Apache Axis | =1.1-rc1 | |
Apache Axis | =1.1-rc2 | |
Apache Axis | =1.2 | |
Apache Axis | =1.2-alpha | |
Apache Axis | =1.2-beta1 | |
Apache Axis | =1.2-beta2 | |
Apache Axis | =1.2-beta3 | |
Apache Axis | =1.2-rc1 | |
Apache Axis | =1.2-rc2 | |
Apache Axis | =1.2-rc3 | |
Apache Axis | =1.2.1 | |
Apache Axis | =1.3 | |
maven/axis:axis | <=1.4 | |
maven/org.apache.axis:axis | <=1.4 | |
IBM Security Directory Suite VA | <=8.0.1-8.0.1.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3596 is a vulnerability in Apache Axis and Axis2 that allows a remote attacker to conduct spoofing attacks.
The severity of CVE-2014-3596 is medium with a CVSS score of 5.8.
CVE-2014-3596 affects Apache Axis versions up to and including 1.4.
To fix the CVE-2014-3596 vulnerability, it is recommended to upgrade to a patched version of Apache Axis.
You can find more information about CVE-2014-3596 at the following references: [link1], [link2], [link3].