Apache CXF CVE-2018-8039 TLS Hostname Verification Security Bypass Vulnerability

Bugtraq ID: 106357
Class: Design Error
CVE: CVE-2018-8039
Remote: Yes
Local: No
Published: Jun 29 2018 12:00AM
Updated: Jul 17 2019 09:00AM
Credit: The vendor reported this issue.
Vulnerable: SAP HANA 1.00
Redhat Virtualization 4
Redhat Single Sign-On 7.0
+ Redhat Linux 6.2 E sparc
+ Redhat Linux 6.2 E i386
+ Redhat Linux 6.2 E alpha
+ Redhat Linux 6.2 sparc
+ Redhat Linux 6.2 i386
+ Redhat Linux 6.2 alpha
Redhat Openshift Application Runtimes 1.0
Redhat Jboss EAP 6
Redhat JBoss Data Virtualization 6.0.0
Redhat JBoss BRMS 6.0
Redhat JBoss BPMS 6.0
Oracle Retail Order Broker 5.2
Oracle Retail Order Broker 15.0
Oracle FLEXCUBE Private Banking 12.1
Oracle FLEXCUBE Private Banking 12.0.3
Oracle FLEXCUBE Private Banking 12.0.1
Oracle Enterprise Manager Base Platform 13.3.0.0.0
Oracle Enterprise Manager Base Platform 13.2.0.0.0
Oracle Enterprise Manager Base Platform 12.1.0.5.0
Oracle Communications Diameter Signaling Router 8.2
Oracle Communications Diameter Signaling Router 8.1
Oracle Communications Diameter Signaling Router 8.0
Apache Cxf 3.2.4
Apache Cxf 3.2.3
Apache Cxf 3.2.2
Apache Cxf 3.2.1
Apache Cxf 3.2
Apache Cxf 3.1.15
Apache Cxf 3.1.14
Apache Cxf 3.1.13
Apache Cxf 3.1.12
Apache Cxf 3.1.11
Apache Cxf 3.1.8
Apache Cxf 3.1.7
Apache Cxf 3.1.3
Apache Cxf 3.1.2
Apache Cxf 3.1.1
Apache Cxf 3.1
Apache Cxf 2.7.18
Apache Cxf 2.7.17
Apache Cxf 2.7.16
Apache Cxf 2.7.15
Apache Cxf 2.7.14
Apache Cxf 2.7.13
Apache Cxf 2.7.10
Apache Cxf 2.7.7
Apache Cxf 2.5.6
Apache Cxf 2.7.9
Apache Cxf 2.7.8
Apache Cxf 2.7.6
Apache Cxf 2.7.5
Apache Cxf 2.7.4
Apache Cxf 2.7.3
Apache Cxf 2.7.2
Apache Cxf 2.7.12
Apache Cxf 2.7.11
Apache Cxf 2.7.1
Apache Cxf 2.7.0
Apache Cxf 2.6.9
Apache Cxf 2.6.8
Apache Cxf 2.6.7
Apache Cxf 2.6.6
Apache Cxf 2.6.5
Apache Cxf 2.6.4
Apache Cxf 2.6.3
Apache Cxf 2.6.2
Apache Cxf 2.6.14
Apache Cxf 2.6.13
Apache Cxf 2.6.12
Apache Cxf 2.6.11
Apache Cxf 2.6.10
Apache Cxf 2.6.1
Apache Cxf 2.6.0
Apache Cxf 2.5.9
Apache Cxf 2.5.8
Apache Cxf 2.5.7
Apache Cxf 2.5.5
Apache Cxf 2.5.4
Apache Cxf 2.5.3
Apache Cxf 2.5.2
Apache Cxf 2.5.1
Apache Cxf 2.5.0
Apache Cxf 2.4.7
Apache Cxf 2.4.6
Apache Cxf 2.4.5
Apache Cxf 2.4.4
Apache Cxf 2.4.3
Apache Cxf 2.4.2
Apache Cxf 2.4.1
Apache Cxf 2.4.0
Not Vulnerable: Apache Cxf 3.2.5
Apache Cxf 3.1.16


 

Privacy Statement
Copyright 2010, SecurityFocus