Improper Certificate Validation in Spring AMQP - CVE-2018-11087

 

Improper Certificate Validation in Spring AMQP - CVE-2018-11087

Published: December 19, 2023


Vulnerability identifier: #VU84551
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-11087
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to lack of hostname validation. A remote attacker that has the ability to intercept traffic would be able to view data in transit.


Affected software

Spring AMQP
IBM Qradar SIEM
Storage Protect Client
Storage Protect for Space Management
Storage Protect for Virtual Environments: Data Protection for VMware

How to mitigate CVE-2018-11087

Install updates from vendor's website.

Spring AMQP - addressed in versions 1.7.10, 2.0.6
Storage Protect Client - update to 8.1.20.0
Storage Protect for Space Management - update to 8.1.20.0
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.1.20.0

External References

Related Security Bulletins