PT-2020-7102 · Red Hat+1 · Jbossws+9

Juraj Somorovsky

+2

·

Published

2020-03-11

·

Updated

2023-02-13

·

CVE-2011-2487

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache WSS4J versions prior to 1.6.5 JBossWS (affected versions not specified) Redhat JBoss Business Rules Management System (affected versions not specified) Redhat JBoss Enterprise Application Platform (affected versions not specified) Redhat JBoss Enterprise SOA Platform (affected versions not specified) Redhat JBoss Enterprise Web Platform (affected versions not specified) Redhat JBoss Middleware (affected versions not specified) Redhat JBoss Portal (affected versions not specified) Redhat JBoss Web Services (affected versions not specified) Apache CXF (affected versions not specified)
Description The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in the affected software are susceptible to a Bleichenbacher attack, which is a type of chosen-ciphertext attack. This weakness allows an attacker to recover the symmetric key and conduct further attacks. The issue is related to the use of a weak symmetric encryption protocol.
Recommendations For Apache WSS4J versions prior to 1.6.5, update to version 1.6.5 or later. For JBossWS, Redhat JBoss Business Rules Management System, Redhat JBoss Enterprise Application Platform, Redhat JBoss Enterprise SOA Platform, Redhat JBoss Enterprise Web Platform, Redhat JBoss Middleware, Redhat JBoss Portal, Redhat JBoss Web Services, and Apache CXF, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

CVE-2011-2487
GHSA-4QQF-HMV6-R6WH
RHSA-2013:0191
RHSA-2013:0192
RHSA-2013:0193
RHSA-2013:0195
RHSA-2013:0196
RHSA-2013:0197

Affected Products

Apache Cxf
Apache Wss4J
Jbossws
Redhat Jboss Business Rules Management System
Red Hat Jboss Enterprise Application Platform
Red Hat Jboss Enterprise Portal Platform
Red Hat Enterprise Web Platform
Redhat Jboss Middleware
Red Hat Jboss Portal
Redhat Jboss Web Services