Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Dennis Kupser

Researcher fromRuhr University Bochum
#20470of 53,633
12.5Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2017-6437
7.5
2017-10-30
Apache · Apache Wss4J · CVE-2015-0226
**Name of the Vulnerable Software and Affected Versions** Apache WSS4J versions prior to 1.6.17 Apache WSS4J versions 2.0.x prior to 2.0.2 **Description** The issue allows remote attackers to recover the plaintext form of a symmetric key via a series of crafted messages, due to improper information leakage about decryption failures when decrypting an encrypted key or message data. **Recommendations** For Apache WSS4J versions prior to 1.6.17, update to version 1.6.17 or later. For Apache WSS4J versions 2.0.x prior to 2.0.2, update to version 2.0.2 or later.
PT-2015-4532
5.0
2015-02-12
Apache · Apache Wss4J · CVE-2015-0227
**Name of the Vulnerable Software and Affected Versions** Apache WSS4J versions 1.6.16 and earlier, 2.x versions prior to 2.0.2 **Description** The issue allows remote attackers to bypass the `requireSignedEncryptedDataElements` configuration through vectors related to "wrapping attacks". This enables attackers to evade security measures. **Recommendations** For Apache WSS4J versions 1.6.16 and earlier, update to version 1.6.17 or later. For Apache WSS4J 2.x versions prior to 2.0.2, update to version 2.0.2 or later.