PT-2013-1562 · Apache · Apache Cxf

Published

2013-01-05

·

Updated

2023-02-13

·

CVE-2012-2378

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache CXF versions 2.4.5 through 2.4.7 Apache CXF versions 2.5.1 through 2.5.3 Apache CXF versions 2.6.x before 2.6.1
Description The issue allows remote attackers to bypass certain policies, including AlgorithmSuite, SignedParts, SignedElements, EncryptedParts, and EncryptedElements, due to improper enforcement of child policies of a WS-SecurityPolicy 1.1 SupportingToken policy on the client side.
Recommendations For Apache CXF versions 2.4.5 through 2.4.7, update to a version outside of this range to resolve the issue. For Apache CXF versions 2.5.1 through 2.5.3, update to a version outside of this range to resolve the issue. For Apache CXF versions 2.6.x before 2.6.1, update to version 2.6.1 or later to resolve the issue.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2012-2378
GHSA-VJPC-VF4F-82QG
RHSA-2012:1591
RHSA-2012:1592

Affected Products

Apache Cxf