Improper Certificate Validation in Apache Commons HttpClient - CVE-2012-5783

 

Improper Certificate Validation in Apache Commons HttpClient - CVE-2012-5783

Published: September 13, 2023


Vulnerability identifier: #VU80741
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-5783
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a man-in-the-middle attack to spoof SSL servers via an arbitrary valid certificate.

The vulnerability exists due to Apache Commons HttpClient does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate. A remote attacker can perform a man-in-the-middle attack to spoof SSL servers via an arbitrary valid certificate.


Affected software

Apache Commons HttpClient
Control Desk
Netezza Appliance
Operations Analytics - Log Analysis
ApplinX
B2B Advanced Communications
Multi-Enterprise Integration Gateway
Analytics Content Hub
StreamSets Data Collector
IBM Engineering Lifecycle Optimization - Publishing
IBM Engineering Systems Design Rhapsody
IBM Workload Automation
watsonx.data
IBM App Connect for Healthcare
Cloud Pak for Security (CP4S)
IBM Tivoli Application Dependency Discovery Manager
IBM Cloud Pak for Data System
QRadar User Behavior Analytics
IBM Maximo Asset Management
IBM Cloud Application Performance Management (APM)
NetWorker
IBM Cloud Pak for Business Automation
IBM VIOS
Fuse
IBM TRIRIGA
IBM AIX

How to mitigate CVE-2012-5783

Install updates from vendor's website.

Netezza Appliance - update to 1.0.0.1
Operations Analytics - Log Analysis - update to 1.3.8.3 IF1
watsonx.data - update to 2.2.1
B2B Advanced Communications - update to 1.0.0.8
Multi-Enterprise Integration Gateway - update to 1.0.0.8
Cloud Pak for Security (CP4S) - update to 1.10.14.0
IBM Cloud Pak for Data System - update to 2.0.2.1
Analytics Content Hub - update to 2.3
IBM VIOS - addressed in versions 3.1.2.60, 3.1.3.40, 3.1.4.20
IBM TRIRIGA - addressed in versions 3.6.1.3, 3.7.0.1, 3.8.0.1, 4.0.2, 4.1.1
QRadar User Behavior Analytics - update to 4.1.9
StreamSets Data Collector - update to 7.0.0
IBM Engineering Lifecycle Optimization - Publishing - addressed in versions 7.0.2.36, 7.0.3.18, 7.1.0.5
IBM AIX - addressed in versions 7.1.5 SP12, 7.2.5 SP06, 7.3.0 SP03, 7.3.1 SP02
IBM Maximo Asset Management - addressed in versions 7.6.1.2.36, 7.6.1.3.11
Fuse - update to 7.12.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
IBM Engineering Systems Design Rhapsody - addressed in versions 9.0.1.0.6, 9.0.2.0.2, 10.0.0.1
IBM Workload Automation - addressed in versions 9.5.0.7, 10.1.0.5, 10.2.2
NetWorker - addressed in versions 19.9.0.6, 19.10.0.3
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.24, 23.0.1.2

External References

Related Security Bulletins