Forum Discussion

jgmyers_43188's avatar
jgmyers_43188
Icon for Nimbostratus rankNimbostratus
Nov 30, 2012

Hostname checking vulnerability in axis

How is F5 addressing CVE-2012-5784, the gaping security hole where axis fails to verify the hostname in the SSL certificate?

 

 

1 Reply

  • Axis is a 3rd party tool that accesses our API. I would expect this to be something that Apache should work on patching. Since F5 isn't the developer for Axis, how to you recommend we address the issue?

     

    -Joe