Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-5633

Опубликовано: 08 фев. 2013
Источник: redhat
CVSS2: 6.4
EPSS Низкий

Описание

The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss BRMS 5SecurityAffected
Red Hat JBoss SOA Platform 5SecurityAffected
Fuse ESB Enterprise 7.1.0FixedRHSA-2013:064914.03.2013
JBEWP 5 for RHEL 5apache-cxfFixedRHSA-2013:025913.02.2013
JBEWP 5 for RHEL 6apache-cxfFixedRHSA-2013:025913.02.2013
JBoss Enterprise BRMS Platform 5.3FixedRHSA-2013:074315.04.2013
Red Hat JBoss Enterprise Application Platform 5.2FixedRHSA-2013:025613.02.2013
Red Hat JBoss Enterprise Application Platform 5 for RHEL 4apache-cxfFixedRHSA-2013:025713.02.2013
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5apache-cxfFixedRHSA-2013:025713.02.2013
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6apache-cxfFixedRHSA-2013:025713.02.2013

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=889008apache-cxf: Bypass of security constraints on WS endpoints when using WSS4JInInterceptor

EPSS

Процентиль: 84%
0.02299
Низкий

6.4 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 13 лет назад

The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.

nvd
почти 13 лет назад

The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.

debian
почти 13 лет назад

The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6 ...

github
больше 3 лет назад

Improper Authentication in Apache CXF

EPSS

Процентиль: 84%
0.02299
Низкий

6.4 Medium

CVSS2