Apache Axis and Axis2/Java SSL Certificate Validation Security Bypass Vulnerability
12 Dec. 2012
Summary
Apache Axis and Axis2/Java are prone to a security-bypass vulnerability because the application fails to properly validate SSL certificates from the server.
Apache Axis could allow a remote attacker to conduct spoofing attacks, caused by the failure to verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate. By persuading a victim to visit a Web site containing a specially-crafted certificate, an attacker could exploit this vulnerability using man-in-the-middle techniques to spoof an SSL server.