PT-2014-2052 · Apache · Apache Cxf+1

Publicado

2014-10-30

·

Atualizado

2022-05-13

·

CVE-2014-3623

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache WSS4J versions 1.6.17 and earlier, 2.x versions prior to 2.0.2 Apache CXF versions 2.7.x prior to 2.7.13, 3.0.x prior to 3.0.2
Description The issue is related to the improper enforcement of SAML SubjectConfirmation method security semantics when using TransportBinding. This allows remote attackers to conduct spoofing attacks. The vulnerability is associated with deficiencies in the authentication procedure, which can be exploited by a remote attacker to bypass the authentication process.
Recommendations For Apache WSS4J versions 1.6.17 and earlier, update to version 1.6.17 or later. For Apache WSS4J 2.x versions prior to 2.0.2, update to version 2.0.2 or later. For Apache CXF versions 2.7.x prior to 2.7.13, update to version 2.7.13 or later. For Apache CXF versions 3.0.x prior to 3.0.2, update to version 3.0.2 or later.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-06637
CVE-2014-3623
GHSA-99V3-9X35-C5VF
MGASA-2014-0552
RHSA-2014:2019

Produtos afetados

Apache Cxf
Apache Wss4J