Man-in-the-middle attack in Apache CXF - CVE-2018-8039

 

Man-in-the-middle attack in Apache CXF - CVE-2018-8039

Published: June 28, 2018 / Updated: June 29, 2018


Vulnerability identifier: #VU13523
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-8039
CWE-ID: CWE-300
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to conduct man-in-the-middle attack on the target system.

The weakness exists due to improper verification of TLS hostnames when used with the 'com.sun.net.ssl' implementation. A remote attacker can conduct a man-in-the-middle attack and bypass the hostname verification.

Affected software

Apache CXF
Tivoli Network Manager IP Edition
Dell Support Assist Enterprise
Oracle Retail Order Broker
Oracle FLEXCUBE Private Banking
SAP Enterprise Architecture Designer
IBM Intelligent Operations Center
Oracle Communications Session Report Manager
Oracle Communications Diameter Signaling Router (DSR)
Enterprise Manager Base Platform
Oracle Communications Session Route Manager
IBM Security Guardium
Voice Gateway

How to mitigate CVE-2018-8039

Update to version 3.1.16, 3.2.5.

Apache CXF - addressed in versions 3.1.16, 3.2.5
Dell Support Assist Enterprise - update to 4.00.06.00
IBM Intelligent Operations Center - update to 5.2.4
Voice Gateway - addressed in versions 1.0.8.2, 1.0.8.6

External References

Related Security Bulletins