PT-2013-2181 · Apache · Apache Cxf

Colm O Heigeartaigh

·

Published

2013-03-12

·

Updated

2023-02-13

·

CVE-2013-0239

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache CXF versions 2.5.0 through 2.5.9 Apache CXF versions 2.6.0 through 2.6.6 Apache CXF versions 2.7.0 through 2.7.3
Description The issue allows remote attackers to bypass authentication when the plaintext UsernameToken WS-SecurityPolicy is enabled. This occurs via a security header of a SOAP request containing a UsernameToken element that lacks a password child element.
Recommendations For Apache CXF versions 2.5.0 through 2.5.9, update to version 2.5.9 or later. For Apache CXF versions 2.6.0 through 2.6.6, update to version 2.6.6 or later. For Apache CXF versions 2.7.0 through 2.7.3, update to version 2.7.3 or later.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-0239
GHSA-P5C5-6564-VVR8
RHSA-2013:0644

Affected Products

Apache Cxf