PT-2021-11168 · Unknown · Jbcs Httpd

Published

2021-01-07

·

Updated

2021-01-14

·

CVE-2020-25680

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: JBCS httpd version 2.4.37 SP3
Description: A flaw was found in JBCS httpd where it uses a back-end worker SSL certificate with the keystore file's ID as 'unknown'. This causes the validation of the certificate to stop working, allowing the connection to the back-end work even when the CN and hostname do not match. The highest threat from this issue is to data integrity.
Recommendations: For version 2.4.37 SP3, consider disabling the use of back-end worker SSL certificates with the keystore file's ID as 'unknown' until a patch is available. Restrict access to the back-end work to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-25680
RHSA-2020:4384

Affected Products

Jbcs Httpd