Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-0239

Опубликовано: 08 фев. 2013
Источник: redhat
CVSS2: 6.4

Описание

Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request containing a UsernameToken element that lacks a password child element.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Portal 6cxfAffected
Fuse ESB Enterprise 7.1.0FixedRHSA-2013:064914.03.2013
Red Hat JBoss Enterprise Application Platform 6.0FixedRHSA-2013:064513.03.2013
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5apache-cxfFixedRHSA-2013:064413.03.2013
Red Hat JBoss Enterprise Application Platform 6 for RHEL 6apache-cxfFixedRHSA-2013:064413.03.2013
Red Hat JBoss Portal 6.0FixedRHSA-2013:074916.04.2013

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=905722apache-cxf: UsernameTokenPolicyValidator and UsernameTokenInterceptor allow empty passwords to authenticate

6.4 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 13 лет назад

Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request containing a UsernameToken element that lacks a password child element.

nvd
больше 13 лет назад

Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request containing a UsernameToken element that lacks a password child element.

debian
больше 13 лет назад

Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, w ...

github
больше 4 лет назад

Improper Authentication in Apache CXF

6.4 Medium

CVSS2