CVE-2012-5783: Apache Httpclient

Medium severity, CVSS 5.8. EPSS: 9.2% chance of exploitation in the next 30 days.

Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Affected products

  • Apache Httpclient: version 3.1 only
  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.04 only

Published 2012-11-04. Last modified 2026-06-16.