Input validation error in Axis - CVE-2012-5784

 

Input validation error in Axis - CVE-2012-5784

Published: February 13, 2023


Vulnerability identifier: #VU72146
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-5784
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to Apache Axis did not verify that the server host name matched the domain name in the subject's Common Name (CN) or subjectAltName field in X.509 certificates. A remote attacker can pass specially crafted input to the application and spoof an SSL server if they had a certificate that was valid for any domain name.


Affected software

Axis
IBM Integration Bus
IBM Cloud Pak for Business Automation
IBM Maximo Asset Management
IBM Maximo Application Suite
IBM App Connect Enterprise
IBM Cloud Pak System
System Storage Support for Microsoft Volume Shadow Copy Service and Virtual Disk Service (VSS)
IBM Cognos Analytics

How to mitigate CVE-2012-5784

Install updates from vendor's website.

IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF007, 24.0.1-IF006, 25.0.0-IF003
IBM Cloud Pak System - update to 2.3.4.0
System Storage Support for Microsoft Volume Shadow Copy Service and Virtual Disk Service (VSS) - update to 4.19.1.3
IBM Maximo Asset Management - addressed in versions 7.6.1.2.0.29, 7.6.1.3.0.4
IBM Maximo Application Suite - update to 8.4.5
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2

External References

Related Security Bulletins