Lucene search

K
cvelistRedhatCVELIST:CVE-2014-3607
HistoryJan 08, 2018 - 7:00 p.m.

CVE-2014-3607

2018-01-0819:00:00
redhat
www.cve.org
3

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

46.1%

DefaultHostnameVerifier in Ldaptive (formerly vt-ldap) does not properly verify that the server hostname matches a domain name in the subject’s Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

46.1%