VDB

RHSA-2014%3A1836

RHSA-2014%3A1836 PUBLISHED CVSS 5.800000190734863 MEDIUM

It was found that the fix for CVE-2012-5783 was incomplete: the code added to check that the server host name matches the domain name in a subject's Common Name (CN) field in X.509 certificates was flawed. A man-in-the-middle attacker could use this flaw to spoof an SSL server using a specially crafted X.509 certificate.

Risk Scores

CVSS 2.0
5.800000190734863

Affected Products

VendorProductVersions
Red HatRed Hat JBoss Enterprise Application Platform 5.2

Timeline

  • Nov 10, 2014 CVE Published
  • Apr 29, 2026 Distribution Patch
  • Apr 29, 2026 Distribution Patch
  • Apr 29, 2026 Security Advisory
  • Apr 29, 2026 Security Advisory
  • Apr 29, 2026 Security Advisory
  • May 14, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›