CVE-2014-5075: Ignite Realtime Smack API
Medium severity, CVSS 6.8. EPSS: 0.9% chance of exploitation in the next 30 days.
The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x and 2.x when a custom SSLContext is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Affected products
- Ignite Realtime Smack API: up to and including 4.0.1
- Red Hat JBoss Fuse: up to and including 6.1.0
Published 2014-10-25. Last modified 2026-06-17.