Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-2487

Опубликовано: 04 сент. 2012
Источник: redhat
CVSS2: 7.8
EPSS Низкий

Описание

The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.

A flaw was found in JBoss web services where the services used a weak symmetric encryption protocol, PKCS#1 v1.5. An attacker could use this weakness in chosen-ciphertext attacks to recover the symmetric key and conduct further attacks.

Отчет

This flaw affects Apache CXF (WSS4J) and jbossws-native as shipped with various JBoss products. It does not affect JBoss Enterprise Application Platform 6 and JBoss Application Server 7.1.1 and above. These products include WSS4J 1.6.5, which incorporates a fix for this flaw. On affected products, this flaw can be mitigated by using the RSA-OAEP key wrap algorithm, instead of the default RSA-v1.5 algorithm. To use RSA-OAEP, edit the jboss-ws-security configuration file and add the property keyWrapAlgorithm="rsa_oaep" to the encrypt element.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss BRMS 5cxfAffected
Red Hat JBoss Portal 4jbossws-nativeAffected
Red Hat JBoss Portal 5jbossws-nativeAffected
Red Hat JBoss SOA Platform 4.2jbossws-nativeAffected
Red Hat JBoss SOA Platform 4.3jbossws-nativeAffected
Red Hat JBoss SOA Platform 5cxfAffected
JBEWP 5 for RHEL 5aopallianceFixedRHSA-2013:019624.01.2013
JBEWP 5 for RHEL 5apache-cxfFixedRHSA-2013:019624.01.2013
JBEWP 5 for RHEL 5bsh2FixedRHSA-2013:019624.01.2013
JBEWP 5 for RHEL 5glassfish-jaxbFixedRHSA-2013:019624.01.2013

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-327
https://bugzilla.redhat.com/show_bug.cgi?id=713539jbossws: Prone to Bleichenbacher attack against to be distributed symmetric key

EPSS

Процентиль: 65%
0.0049
Низкий

7.8 High

CVSS2

Связанные уязвимости

CVSS3: 5.9
nvd
почти 6 лет назад

The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.

CVSS3: 5.9
github
почти 4 года назад

Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J

EPSS

Процентиль: 65%
0.0049
Низкий

7.8 High

CVSS2

Уязвимость CVE-2011-2487