Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-0226

Опубликовано: 30 окт. 2017
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5
CVSS3: 7.5

Описание

Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series of crafted messages. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-2487.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

1.6.15-2
cosmic

not-affected

1.6.15-2
devel

not-affected

1.6.15-2
disco

not-affected

1.6.15-2
esm-apps-legacy/xenial

not-affected

1.6.15-2
esm-apps/bionic

not-affected

1.6.15-2
esm-apps/xenial

not-affected

1.6.15-2
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needed]
lucid

not-affected

1.5.7-0ubuntu1

Показывать по

Ссылки на источники

EPSS

Процентиль: 92%
0.05501
Низкий

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

redhat
больше 11 лет назад

Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series of crafted messages. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-2487.

CVSS3: 7.5
nvd
почти 9 лет назад

Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series of crafted messages. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-2487.

CVSS3: 7.5
debian
почти 9 лет назад

Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks inf ...

CVSS3: 7.5
github
больше 4 лет назад

Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J

EPSS

Процентиль: 92%
0.05501
Низкий

5 Medium

CVSS2

7.5 High

CVSS3