Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:6891
HistoryJun 29, 2018 - 5:13 a.m.

Hostname Verification Bypass

2018-06-2905:13:30
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.007 Low

EPSS

Percentile

80.9%

Apache CXF is vulnerable to hostname verification bypass. The vulnerability exists when CXF is used with the com.sun.net.ssl stack, leading to an error in TLS hostname verification which make CXF clients susceptible to man-in-the-middle attack.

References