Input validation error in Axis - CVE-2014-3596

 

Input validation error in Axis - CVE-2014-3596

Published: August 27, 2014 / Updated: August 10, 2020


Vulnerability identifier: #VU41375
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-3596
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

The getCN function in Apache Axis 1.4 and earlier does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5784. <a href="http://cwe.mitre.org/data/definitions/297.html" target="_blank">CWE-297: Improper Validation of Certificate with Host Mismatch</a>


Affected software

Axis
Amazon Linux AMI
IBM Integration Bus
IBM Cloud Pak for Business Automation
IBM Maximo Asset Management
IBM Maximo Application Suite
IBM App Connect Enterprise
IBM Cloud Pak System
System Storage Support for Microsoft Volume Shadow Copy Service and Virtual Disk Service (VSS)
IBM Cognos Analytics

How to mitigate CVE-2014-3596

Install update from vendor's website.

IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF007, 24.0.1-IF006, 25.0.0-IF003
IBM Cloud Pak System - update to 2.3.4.0
System Storage Support for Microsoft Volume Shadow Copy Service and Virtual Disk Service (VSS) - update to 4.19.1.3
IBM Maximo Asset Management - addressed in versions 7.6.1.2.0.29, 7.6.1.3.0.4
IBM Maximo Application Suite - update to 8.4.5
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2

External References

Related Security Bulletins