Описание
Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."
Отчет
Not Vulnerable. This issue does not affect the version of axis as shipped with JBoss Developer Studio 5 and 6, JBoss Enterprise Portal Platform 5.2.2 and 6.0.0, Red Hat Enterprise Linux 5 and 6, and Red Hat Enterprise Virtualization Manager 3.1.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | axis | Not affected | ||
| Red Hat Enterprise Linux 6 | axis | Not affected |
Показывать по
10
Дополнительная информация
Статус:
Important
https://bugzilla.redhat.com/show_bug.cgi?id=856755axis2: vulnerable to XML signature wrapping attacks
5.8 Medium
CVSS2
Связанные уязвимости
nvd
больше 13 лет назад
Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."
5.8 Medium
CVSS2