Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-0239

Опубликовано: 08 фев. 2013
Источник: redhat
CVSS2: 6.4

Описание

Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request containing a UsernameToken element that lacks a password child element.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Web Server 1eap-5Not affected
Red Hat JBoss Portal 6cxfAffected
Fuse ESB Enterprise 7.1.0FixedRHSA-2013:064914.03.2013
Red Hat JBoss Enterprise Application Platform 6.0FixedRHSA-2013:064513.03.2013
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5apache-cxfFixedRHSA-2013:064413.03.2013
Red Hat JBoss Enterprise Application Platform 6 for RHEL 6apache-cxfFixedRHSA-2013:064413.03.2013
Red Hat JBoss Portal 6.0FixedRHSA-2013:074916.04.2013

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=905722apache-cxf: UsernameTokenPolicyValidator and UsernameTokenInterceptor allow empty passwords to authenticate

6.4 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 13 лет назад

Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request containing a UsernameToken element that lacks a password child element.

nvd
почти 13 лет назад

Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request containing a UsernameToken element that lacks a password child element.

debian
почти 13 лет назад

Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, w ...

github
почти 4 года назад

Improper Authentication in Apache CXF

6.4 Medium

CVSS2