Логотип exploitDog
bind:CVE-2012-5575
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2012-5575

Количество 3

Количество 3

redhat логотип

CVE-2012-5575

почти 13 лет назад

Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack."

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2012-5575

больше 12 лет назад

Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack."

CVSS2: 6.4
EPSS: Низкий
github логотип

GHSA-7v5v-9v8r-w864

больше 3 лет назад

Inadequate Encryption Strength in Apache CXF

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2012-5575

Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack."

CVSS2: 7.8
10%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-5575

Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack."

CVSS2: 6.4
10%
Низкий
больше 12 лет назад
github логотип
GHSA-7v5v-9v8r-w864

Inadequate Encryption Strength in Apache CXF

10%
Низкий
больше 3 лет назад

Уязвимостей на страницу