Apache Axis2/C SSL Certificate Validation Security Bypass Vulnerability
BID:57267
Info
Apache Axis2/C SSL Certificate Validation Security Bypass Vulnerability
| Bugtraq ID: | 57267 |
| Class: | Design Error |
| CVE: |
CVE-2012-6107 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 11 2013 12:00AM |
| Updated: | Jan 11 2013 12:00AM |
| Credit: | Seth Arnold |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Apache Axis2/C SSL Certificate Validation Security Bypass Vulnerability
Apache Axis2/C is prone to a security-bypass vulnerability because the application fails to properly validate SSL certificates from the server.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
Apache Axis2/C is prone to a security-bypass vulnerability because the application fails to properly validate SSL certificates from the server.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
Exploit / POC
Apache Axis2/C SSL Certificate Validation Security Bypass Vulnerability
An attacker can use readily available network utilities to exploit this issue.
An attacker can use readily available network utilities to exploit this issue.