{"id":"CVE-2012-5817","description":"Codehaus XFire 1.2.6 and earlier, as used in the Amazon EC2 API Tools Java library and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.","cvssScore":7.4,"cvssVersion":"3.1","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","cvssMetrics":[{"version":"3.1","score":7.4,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"},{"version":"2.0","score":5.8,"vector":"AV:N/AC:M/Au:N/C:P/I:P/A:N","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"cwes":["CWE-295","CWE-20"],"resolved":"NO-EXPLOIT-PUBLISHED","published":"2012-11-04","lastModified":"2026-06-16","affectedProducts":[{"vendor":"amazon","product":"ec2 api tools java library"},{"vendor":"codehaus","product":"xfire","versionEnd":"\u003c=1.2.6"}],"totalAffectedProducts":2,"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/79934","source":"osv","tags":["WEB"]},{"url":"http://www.cs.utexas.edu/~shmat/shmat_ccs12.pdf","source":"osv","tags":["WEB"]}],"reasoning":{"decidingSource":"no-exploit-published","decidingReason":"This CVE is not listed in CISA KEV, CISA Vulnrichment records no active exploitation, and no reviewed exploit catalogue carries an entry for it. Nobody has published something a stranger can run, so it is not a candidate for a rule ahead of the ones where somebody has; an upstream fix path does exist, so the remediation half of the candidacy still holds. This is a statement about what has been published, not about whether the defect is reachable or serious.","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"no-match"},{"rule":"non-java-upstream","stage":"scope","outcome":"no-match"},{"rule":"oracle-component","stage":"scope","outcome":"no-match"},{"rule":"osv-maven","stage":"scope","outcome":"matched","status":"QUEUED-FOR-REVIEW","detail":"Maven packages: org.codehaus.xfire:xfire-core"},{"rule":"patch-hint","stage":"disposition","outcome":"no-match"},{"rule":"open-source-maven","stage":"disposition","outcome":"matched","status":"MITIGATION-CANDIDATE","detail":"Open-source Maven artifact indexed by OSV (Maven packages: org.codehaus.xfire:xfire-core). The source is public, which makes an ARMR patch rule a candidate; nothing here establishes that one can be written."},{"rule":"poc-derivable","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit","stage":"disposition","outcome":"skipped"},{"rule":"secure-rule-match","stage":"disposition","outcome":"no-match"},{"rule":"below-action-threshold","stage":"disposition","outcome":"no-match","detail":"Severity is HIGH — only MEDIUM/LOW are deprioritized"},{"rule":"no-exploit-published","stage":"disposition","outcome":"matched","status":"NO-EXPLOIT-PUBLISHED","detail":"No working exploit has been published, and an upstream fix path does exist, so the remediation half of the candidacy still holds.","decisive":true}],"affectedProducts":[{"vendor":"amazon","product":"ec2_api_tools_java_library","isKnown":false,"cpe":"cpe:2.3:a:amazon:ec2_api_tools_java_library:-:*:*:*:*:*:*:*"},{"vendor":"codehaus","product":"xfire","isKnown":false,"cpe":"cpe:2.3:a:codehaus:xfire:*:*:*:*:*:*:*:*"}],"affectedPackages":[{"name":"org.codehaus.xfire:xfire-core","introduced":"0","lastAffected":"1.2.6"}]},"assessment":{"record":{"state":"active"},"protection":{"level":"none"},"action":{"state":"unverified","type":"patch-rule"},"review":{"state":"automated","basis":"upstream-data"}},"signals":{"hasPOC":false,"pocCount":0},"kev":{"inKEV":false},"epss":{"available":true,"score":0.00778,"percentile":0.53955},"ssvc":{"available":false}}