Improper Certificate Validation in Spring AMQP - CVE-2018-11087
Published: December 19, 2023
Vulnerability identifier: #VU84551
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-11087
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to lack of hostname validation. A remote attacker that has the ability to intercept traffic would be able to view data in transit.
Affected software
Spring AMQP
IBM Qradar SIEM
Storage Protect Client
Storage Protect for Space Management
Storage Protect for Virtual Environments: Data Protection for VMware
IBM Qradar SIEM
Storage Protect Client
Storage Protect for Space Management
Storage Protect for Virtual Environments: Data Protection for VMware
How to mitigate CVE-2018-11087
Install updates from vendor's website.
Spring AMQP - addressed in versions 1.7.10, 2.0.6
Storage Protect Client - update to 8.1.20.0
Storage Protect for Space Management - update to 8.1.20.0
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.1.20.0
Storage Protect Client - update to 8.1.20.0
Storage Protect for Space Management - update to 8.1.20.0
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.1.20.0