CVE-2014-3604

Impact:
Important
Public Date:
2014-08-22
CWE:
CWE-228->CWE-297
Bugzilla:
1131803: CVE-2014-3604 Not Yet Commons SSL: Hostname verification susceptible to MITM attack
It was discovered that the implementation used by the Not Yet Commons SSL project to check that the server hostname matches the domain name in the subject's CN field was flawed. This could be exploited by a man-in-the-middle attacker by spoofing a valid certificate using a specially crafted subject.

Find out more about CVE-2014-3604 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

Red Hat JBoss SOA Platform 4 is now in Phase 3, Extended Life Support, of its life cycle. This issue has been rated as having Important security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat JBoss Middleware and Red Hat JBoss Operations Network Product Update and Support Policy: https://access.redhat.com/support/policy/updates/jboss_notes/

CVSS v2 metrics

Base Score 5.8
Base Metrics AV:N/AC:M/Au:N/C:P/I:P/A:N
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact None

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat JBoss SOA Platform 5.3 RHSA-2015:1888 2015-10-12

Affected Packages State

Platform Package State
Red Hat JBoss Enterprise SOA Platform 4 commons-ssl Will not fix

Acknowledgements

This issue was discovered by Arun Babu Neelicattu of Red Hat Product Security.

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.