PT-2013-1808 · Apache · Apache Cxf

CVE-2012-5575

·

Publicado

2013-08-19

·

Atualizado

2023-02-13

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache CXF versions 2.5.x through 2.5.9 Apache CXF versions 2.6.x through 2.6.6 Apache CXF versions 2.7.x through 2.7.3
Description The issue allows remote attackers to force the use of weaker cryptographic algorithms than intended, making it easier to decrypt communications. This is due to the failure to verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting.
Recommendations For Apache CXF versions 2.5.x through 2.5.9, update to version 2.5.10 or later. For Apache CXF versions 2.6.x through 2.6.6, update to version 2.6.7 or later. For Apache CXF versions 2.7.x through 2.7.3, update to version 2.7.4 or later.

Correção

Inadequate Encryption Strength

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-5575
GHSA-7V5V-9V8R-W864
RHSA-2013:0834
RHSA-2013:0839
RHSA-2013:0873
RHSA-2013:0874

Produtos afetados

Apache Cxf