Vulnerability Name:

CVE-2012-5662 (CCN-82984)

Assigned:2012-10-24
Published:2013-03-21
Updated:2017-08-29
Summary:x3270 before 3.3.12ga12 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:5.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N)
4.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-310
Vulnerability Consequences:Other
References:Source: MITRE
Type: CNA
CVE-2012-5662

Source: OSVDB
Type: UNKNOWN
91572

Source: CCN
Type: SA52650
x3270 SSL Certificate Verification Security Issue

Source: SECUNIA
Type: UNKNOWN
52650

Source: CONFIRM
Type: UNKNOWN
http://sourceforge.net/projects/x3270/files/x3270/3.3.12ga12/

Source: CCN
Type: x3270 Web site
x3270

Source: CCN
Type: Red Hat Bugzilla Bug 889373
CVE-2012-5662 x3270: does not properly validate SSL certificates

Source: CONFIRM
Type: UNKNOWN
https://bugzilla.redhat.com/show_bug.cgi?id=889373

Source: XF
Type: UNKNOWN
x3270-cve20125662-spoofing(82984)

Source: XF
Type: UNKNOWN
x3270-cve20125662-spoofing(82984)

Source: CCN
Type: IBM Security Bulletin 1283272 (Security Secret Server)
Multiple Vulnerabilities Have Been Identified In IBM Security Secret Server

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2012-5662

Vulnerable Configuration:Configuration 1:
  • cpe:/a:paul_mattes:x3270:3.3.5:*:*:*:*:*:*:*
  • OR cpe:/a:paul_mattes:x3270:3.3.6:*:*:*:*:*:*:*
  • OR cpe:/a:paul_mattes:x3270:3.3.7:*:*:*:*:*:*:*
  • OR cpe:/a:paul_mattes:x3270:3.3.8:-:*:*:*:*:*:*
  • OR cpe:/a:paul_mattes:x3270:3.3.8:p1:*:*:*:*:*:*
  • OR cpe:/a:paul_mattes:x3270:3.3.8:p2:*:*:*:*:*:*
  • OR cpe:/a:paul_mattes:x3270:3.3.8:p3:*:*:*:*:*:*
  • OR cpe:/a:paul_mattes:x3270:3.3.9:ga11:*:*:*:*:*:*
  • OR cpe:/a:paul_mattes:x3270:3.3.9:ga12:*:*:*:*:*:*
  • OR cpe:/a:paul_mattes:x3270:3.3.10:ga3:*:*:*:*:*:*
  • OR cpe:/a:paul_mattes:x3270:3.3.10:ga4:*:*:*:*:*:*
  • OR cpe:/a:paul_mattes:x3270:3.3.10:ga5:*:*:*:*:*:*
  • OR cpe:/a:paul_mattes:x3270:3.3.11:beta2:*:*:*:*:*:*
  • OR cpe:/a:paul_mattes:x3270:3.3.11:beta4:*:*:*:*:*:*
  • OR cpe:/a:paul_mattes:x3270:3.3.11:ga6:*:*:*:*:*:*
  • OR cpe:/a:paul_mattes:x3270:3.3.12:beta6:*:*:*:*:*:*
  • OR cpe:/a:paul_mattes:x3270:3.3.12:ga10:*:*:*:*:*:*
  • OR cpe:/a:paul_mattes:x3270:*:ga11:*:*:*:*:*:* (Version <= 3.3.12)
  • OR cpe:/a:paul_mattes:x3270:3.3.12:ga7:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:ibm:security_secret_server:10.7:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20125662
    V
    CVE-2012-5662
    2022-05-20
    oval:org.opensuse.security:def:26183
    P
    Security update for xorg-x11-server (Important)
    2021-12-14
    oval:org.opensuse.security:def:32244
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP3) (Important)
    2021-12-14
    oval:org.opensuse.security:def:26158
    P
    Security update for binutils (Moderate)
    2021-11-02
    oval:org.opensuse.security:def:33020
    P
    Security update for python36 (Moderate)
    2021-10-09
    oval:org.opensuse.security:def:32189
    P
    Security update for the Linux Kernel (Live Patch 39 for SLE 12 SP3) (Important)
    2021-09-23
    oval:org.opensuse.security:def:32981
    P
    Security update for fetchmail (Moderate)
    2021-08-18
    oval:org.opensuse.security:def:32157
    P
    Security update for qemu (Important)
    2021-07-29
    oval:org.opensuse.security:def:32133
    P
    Security update for libgcrypt (Important)
    2021-06-24
    oval:org.opensuse.security:def:26077
    P
    Security update for apache2 (Important)
    2021-06-17
    oval:org.opensuse.security:def:42731
    P
    x3270-3.3.12-517.12.34 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36324
    P
    x3270-3.3.12-517.12.34 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:32100
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:26032
    P
    Security update for sudo (Important)
    2021-04-20
    oval:org.opensuse.security:def:31609
    P
    Security update for sudo (Important)
    2021-04-20
    oval:org.opensuse.security:def:26215
    P
    Security update for openssl-1_1 (Important)
    2021-03-25
    oval:org.opensuse.security:def:32277
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP3) (Important)
    2021-03-17
    oval:org.opensuse.security:def:31741
    P
    Security update for wpa_supplicant (Important)
    2021-03-09
    oval:org.opensuse.security:def:32238
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP3) (Important)
    2021-02-10
    oval:org.opensuse.security:def:32008
    P
    Security update for the Linux Kernel (Live Patch 31 for SLE 12 SP3) (Important)
    2020-12-07
    oval:org.opensuse.security:def:36057
    P
    x3270-3.3.12-517.12.34 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:42464
    P
    x3270-3.3.12-517.12.34 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:31535
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:31790
    P
    Security update for MozillaFirefox (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32400
    P
    Security update for vim (Important)
    2020-12-01
    oval:org.opensuse.security:def:27055
    P
    x3270 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26649
    P
    wireshark on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31791
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:32456
    P
    Security update for xorg-x11-libX11 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25606
    P
    Security update for libjpeg-turbo (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27287
    P
    ruby on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32299
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31802
    P
    Security update for adns (Important)
    2020-12-01
    oval:org.opensuse.security:def:32505
    P
    enscript on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25607
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26236
    P
    Security update for libvpx (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26299
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:27322
    P
    x3270 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31833
    P
    Security update for bind (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32343
    P
    Security update for spice (Important)
    2020-12-01
    oval:org.opensuse.security:def:31876
    P
    Security update for dhcp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32544
    P
    libMagickCore1-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25618
    P
    Security update for python3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26285
    P
    Security update for the Linux Kernel (Critical)
    2020-12-01
    oval:org.opensuse.security:def:25873
    P
    Security update for libcares2 (Low)
    2020-12-01
    oval:org.opensuse.security:def:26450
    P
    Security update for MozillaThunderbird (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31890
    P
    Security update for exempi (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32566
    P
    libsamplerate on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25682
    P
    Security update for wpa_supplicant (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26324
    P
    Security update for MozillaThunderbird (Important)
    2020-12-01
    oval:org.opensuse.security:def:25874
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:26503
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:31977
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:32610
    P
    unrar on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25810
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26338
    P
    Security update for Chromium (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25885
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:26552
    P
    g3utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31523
    P
    Security update for rsync (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33248
    P
    quagga on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25891
    P
    Security update for libimobiledevice, usbmuxd (Important)
    2020-12-01
    oval:org.opensuse.security:def:26382
    P
    Security update for ffmpeg (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25949
    P
    Security update for icu (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26591
    P
    libmysqlclient15-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31524
    P
    Security update for rsync (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33287
    P
    x3270 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25948
    P
    Security update for libraw (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27020
    P
    python-pam on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26605
    P
    libtiff3 on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.cosmic:def:201256620000000
    V
    CVE-2012-5662 on Ubuntu 18.10 (cosmic) - medium.
    2014-05-27
    oval:com.ubuntu.artful:def:20125662000
    V
    CVE-2012-5662 on Ubuntu 17.10 (artful) - medium.
    2014-05-27
    oval:com.ubuntu.trusty:def:20125662000
    V
    CVE-2012-5662 on Ubuntu 14.04 LTS (trusty) - medium.
    2014-05-27
    oval:com.ubuntu.bionic:def:201256620000000
    V
    CVE-2012-5662 on Ubuntu 18.04 LTS (bionic) - medium.
    2014-05-27
    oval:com.ubuntu.bionic:def:20125662000
    V
    CVE-2012-5662 on Ubuntu 18.04 LTS (bionic) - medium.
    2014-05-27
    oval:com.ubuntu.xenial:def:20125662000
    V
    CVE-2012-5662 on Ubuntu 16.04 LTS (xenial) - medium.
    2014-05-27
    oval:com.ubuntu.xenial:def:201256620000000
    V
    CVE-2012-5662 on Ubuntu 16.04 LTS (xenial) - medium.
    2014-05-27
    oval:com.ubuntu.cosmic:def:20125662000
    V
    CVE-2012-5662 on Ubuntu 18.10 (cosmic) - medium.
    2014-05-27
    oval:com.ubuntu.disco:def:201256620000000
    V
    CVE-2012-5662 on Ubuntu 19.04 (disco) - medium.
    2014-05-27
    oval:com.ubuntu.precise:def:20125662000
    V
    CVE-2012-5662 on Ubuntu 12.04 LTS (precise) - medium.
    2014-05-27
    BACK
    paul_mattes x3270 3.3.5
    paul_mattes x3270 3.3.6
    paul_mattes x3270 3.3.7
    paul_mattes x3270 3.3.8 -
    paul_mattes x3270 3.3.8 p1
    paul_mattes x3270 3.3.8 p2
    paul_mattes x3270 3.3.8 p3
    paul_mattes x3270 3.3.9 ga11
    paul_mattes x3270 3.3.9 ga12
    paul_mattes x3270 3.3.10 ga3
    paul_mattes x3270 3.3.10 ga4
    paul_mattes x3270 3.3.10 ga5
    paul_mattes x3270 3.3.11 beta2
    paul_mattes x3270 3.3.11 beta4
    paul_mattes x3270 3.3.11 ga6
    paul_mattes x3270 3.3.12 beta6
    paul_mattes x3270 3.3.12 ga10
    paul_mattes x3270 * ga11
    paul_mattes x3270 3.3.12 ga7
    ibm security secret server 10.7