Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-5575

Опубликовано: 08 мар. 2013
Источник: redhat
CVSS2: 7.8

Описание

Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack."

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss BRMS 5cxfAffected
Red Hat JBoss BRMS 5jbossws-nativeAffected
Red Hat JBoss Portal 4jbossws-nativeAffected
Red Hat JBoss Portal 5jbossws-nativeAffected
Red Hat JBoss Portal 6cxfAffected
Red Hat JBoss SOA Platform 4jbossws-nativeAffected
Red Hat JBoss SOA Platform 5cxfAffected
Red Hat JBoss SOA Platform 5jbossws-nativeAffected
Fuse ESB Enterprise 7.1.0FixedRHSA-2013:102809.07.2013
JBEWP 5 for RHEL 5apache-cxfFixedRHSA-2013:087428.05.2013

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-327
https://bugzilla.redhat.com/show_bug.cgi?id=880443apache-cxf: XML encryption backwards compatibility attacks

7.8 High

CVSS2

Связанные уязвимости

nvd
почти 13 лет назад

Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack."

github
около 4 лет назад

Inadequate Encryption Strength in Apache CXF

7.8 High

CVSS2