Cryptographic Issues The advisory has been revoked - it doesn't affect any version of package ibm-3270  (opens in a new tab)


Threat Intelligence

EPSS
0.62% (45th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UBUNTU2510-IBM3270-15028078
  • published17 Jan 2026
  • disclosed27 May 2014

Introduced: 27 May 2014

CVE-2012-5662  (opens in a new tab)
CWE-310  (opens in a new tab)

Amendment

The Ubuntu security team deemed this advisory irrelevant for Ubuntu:25.10.

NVD Description

Note: Versions mentioned in the description apply only to the upstream ibm-3270 package and not the ibm-3270 package as distributed by Ubuntu.

x3270 before 3.3.12ga12 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.