Input validation error in Axis - CVE-2014-3596
Published: August 27, 2014 / Updated: August 10, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The getCN function in Apache Axis 1.4 and earlier does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5784. <a href="http://cwe.mitre.org/data/definitions/297.html" target="_blank">CWE-297: Improper Validation of Certificate with Host Mismatch</a>
Affected software
Amazon Linux AMI
IBM Integration Bus
IBM Cloud Pak for Business Automation
IBM Maximo Asset Management
IBM Maximo Application Suite
IBM App Connect Enterprise
IBM Cloud Pak System
System Storage Support for Microsoft Volume Shadow Copy Service and Virtual Disk Service (VSS)
IBM Cognos Analytics
How to mitigate CVE-2014-3596
IBM Cloud Pak System - update to 2.3.4.0
System Storage Support for Microsoft Volume Shadow Copy Service and Virtual Disk Service (VSS) - update to 4.19.1.3
IBM Maximo Asset Management - addressed in versions 7.6.1.2.0.29, 7.6.1.3.0.4
IBM Maximo Application Suite - update to 8.4.5
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2
External References
- http://linux.oracle.com/errata/ELSA-2014-1193.html
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00007.html
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00022.html
- http://rhn.redhat.com/errata/RHSA-2014-1193.html
- http://secunia.com/advisories/61222
- http://www.openwall.com/lists/oss-security/2014/08/20/2
- http://www.securityfocus.com/bid/69295
- http://www.securitytracker.com/id/1030745
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95377
- https://issues.apache.org/jira/browse/AXIS-2905
- https://lists.apache.org/thread.html/44d4e88a5fa8ae60deb752029afe9054da87c5f859caf296fcf585e5@%3Cjava-dev.axis.apache.org%3E
- https://lists.apache.org/thread.html/5e6c92145deddcecf70c3604041dcbd615efa2d37632fc2b9c367780@%3Cjava-dev.axis.apache.org%3E
- https://lists.apache.org/thread.html/8aa25c99eeb0693fc229ec87d1423b5ed5d58558618706d8aba1d832@%3Cjava-dev.axis.apache.org%3E
- https://lists.apache.org/thread.html/a308887782e05da7cf692e4851ae2bd429a038570cbf594e6631cc8d@%3Cjava-dev.axis.apache.org%3E
- https://lists.apache.org/thread.html/de2af12dcaba653d02b03235327ca4aa930401813a3cced8e151d29c@%3Cjava-dev.axis.apache.org%3E
- https://www.oracle.com/security-alerts/cpujan2020.html
Related Security Bulletins
- Input validation error in Axis
- Amazon Linux AMI update for axis
- Multiple vulnerabilities in IBM Maximo Asset Management and IBM Maximo Application Suite
- Multiple vulnerabilities in IBM App Connect Enterprise Toolkit and the IBM Integration Bus Toolkit
- Multiple vulnerabilities in IBM Cognos Analytics
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM System Storage Support for Microsoft Volume Shadow Copy Service and Virtual Disk Service (VSS)
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation