VDB
RHSA-2016:1931
RHSA-2016:1931
PUBLISHED
CVSS 4.800000190734863 MEDIUM
It was found that the fix for CVE-2012-6153 was incomplete: the code added to check that the server hostname matches the domain name in a subject's Common Name (CN) field in X.509 certificates was flawed. A man-in-the-middle attacker could use this flaw to spoof an SSL server using a specially crafted X.509 certificate.
Risk Scores
CVSS 3.0
4.800000190734863
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Fuse 6.2 | |
| Red Hat | Red Hat JBoss A-MQ 6.2 |
Timeline
- Sep 23, 2016 CVE Published
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Security Advisory
- May 14, 2026 CVE Updated
- May 15, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2016:1931 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=jboss.fuse&downloadType=securityPatches&version=6.2.1 advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=jboss.amq&downloadType=securityPatches&version=6.2.1 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2016/rhsa-2016_1931.json advisory
- https://www.cve.org/CVERecord?id=CVE-2014-3577 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1129074 issue
- https://access.redhat.com/security/cve/CVE-2014-3577 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-3577 advisory