V
Scaner-VSvulnerability catalog · v4.2
CVE-2012-5575
CVE
HighConfirmedExploit available

Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorit…

CVSS
7.8
High
EPSS
0.10
p92
Published
2012-01-01
Updated
2012-01-01
Description

Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack."

Tags · CWE
Crypto
CWE-310
CWE-327
CAPEC-20
CAPEC-97
CAPEC-459
CAPEC-473
CAPEC-475
CAPEC-608
CAPEC-614
Affected products
Apache-commons-daemon-eap6Apache-commons-daemon-eap6Apache-commons-daemon-jsvc-eap6Apache-commons-daemon-jsvc-eap6Apache-commons-pool-eap6Apache-commons-pool-eap6Apache-cxfApache-cxfApache-cxfApache-cxfApache-cxfApache-cxfApache-cxfApache-cxf-xjc-utilsApache-cxf-xjc-utilsAtinjectAtinjectAtinject-eap6Atinject-eap6Codehaus-jackson
CVSS vector
AV:N/AC:L/Au:N/C:C/I:N/A:N
Timeline
2012-01-01
Published
2012-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: C
Complete
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.095 · p92
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-473 · CWE-327
└ via CAPEC-473 · CWE-327
Known exploits — Сканер-ВС
CVE-2012-5575
github-poc · https://github.com/tafamace/CVE-2012-5575
Enterprise
Affected software
ProductVendorStatus
apache-commons-daemon-eap6Tracked
apache-commons-daemon-eap6Tracked
apache-commons-daemon-jsvc-eap6Tracked
apache-commons-daemon-jsvc-eap6Tracked
apache-commons-pool-eap6Tracked
apache-commons-pool-eap6Tracked
apache-cxfTracked
apache-cxfTracked
apache-cxfTracked
apache-cxfTracked
apache-cxfTracked
apache-cxfTracked
apache-cxfTracked
apache-cxf-xjc-utilsTracked
apache-cxf-xjc-utilsTracked
atinjectTracked
atinjectTracked
atinject-eap6Tracked
atinject-eap6Tracked
codehaus-jacksonTracked
Source databases
CVE
RED