Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-5575

Опубликовано: 08 мар. 2013
Источник: redhat
CVSS2: 7.8
EPSS Низкий

Описание

Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack."

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss BRMS 5cxfAffected
Red Hat JBoss BRMS 5jbossws-nativeAffected
Red Hat JBoss Enterprise Web Server 1eap-5Affected
Red Hat JBoss Enterprise Web Server 1fuse-esb-enterprise-7Affected
Red Hat JBoss Portal 4jbossws-nativeAffected
Red Hat JBoss Portal 5jbossws-nativeAffected
Red Hat JBoss Portal 6cxfAffected
Red Hat JBoss SOA Platform 4.3jbossws-nativeAffected
Red Hat JBoss SOA Platform 5cxfAffected
Red Hat JBoss SOA Platform 5jbossws-nativeAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-327
https://bugzilla.redhat.com/show_bug.cgi?id=880443apache-cxf: XML encryption backwards compatibility attacks

EPSS

Процентиль: 93%
0.09505
Низкий

7.8 High

CVSS2

Связанные уязвимости

nvd
больше 12 лет назад

Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack."

github
больше 3 лет назад

Inadequate Encryption Strength in Apache CXF

EPSS

Процентиль: 93%
0.09505
Низкий

7.8 High

CVSS2

Уязвимость CVE-2012-5575