Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Apache Axis2/C does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache Axis2/C 加密问题漏洞
Vulnerability Description
Apache Axis2是美国阿帕奇(Apache)软件基金会的一个Web服务的核心支援引擎。Apache Axis2/C是其中的一个C语言开发版本。 Apache Axis2/C中存在安全漏洞,该漏洞源于程序没有对X.509证书的‘subject's Common Name (CN)’或‘subjectAltName’字段中的域名与服务器主机名相匹配。攻击者可通过任意有效的证书利用该漏洞实施中间人攻击,伪造数据,欺骗服务器。
CVSS Information
N/A
Vulnerability Type
N/A