Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-0227

Опубликовано: 10 фев. 2015
Источник: redhat
CVSS2: 4
EPSS Средний

Описание

Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks."

It was found that Apache WSS4J permitted bypass of the requireSignedEncryptedDataElements configuration property via XML Signature wrapping attacks. A remote attacker could use this flaw to modify the contents of a signed request.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6wss4jAffected
Red Hat JBoss BRMS 5wss4jWill not fix
Red Hat JBoss BRMS 6wss4jAffected
Red Hat JBoss Data Virtualization 6wss4jAffected
Red Hat JBoss Enterprise Application Platform 5wss4jWill not fix
Red Hat JBoss Enterprise Web Server 1fuse-6Affected
Red Hat JBoss Enterprise Web Server 1fuse-esb-7Will not fix
Red Hat JBoss Fuse Service Works 6wss4jAffected
Red Hat JBoss Operations Network 2wss4jNot affected
Red Hat JBoss Operations Network 3wss4jAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-358
https://bugzilla.redhat.com/show_bug.cgi?id=1191451wss4j: Apache WSS4J doesn't correctly enforce the requireSignedEncryptedDataElements property

EPSS

Процентиль: 94%
0.13872
Средний

4 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks."

nvd
почти 11 лет назад

Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks."

debian
почти 11 лет назад

Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attacker ...

github
больше 3 лет назад

Improper Access Control in Apache WSS4J

EPSS

Процентиль: 94%
0.13872
Средний

4 Medium

CVSS2