V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2015-0226
DEB
High

Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key o…

CVSS
7.5
High
EPSS
0.05
p90
Published
2015-01-01
Updated
2015-01-01
Description

Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series of crafted messages. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-2487.

Tags · CWE
Pre-authCrypto
CWE-327
CAPEC-20
CAPEC-97
CAPEC-459
CAPEC-473
CAPEC-475
CAPEC-608
CAPEC-614
Affected products
Apache-commons-cli-eap6Apache-commons-cli-eap6Apache-commons-codec-eap6Apache-commons-codec-eap6Apache-commons-configuration-eap6Apache-commons-configuration-eap6Apache-commons-daemon-eap6Apache-commons-daemon-eap6Apache-commons-daemon-eap6Apache-commons-io-eap6Apache-commons-io-eap6Apache-commons-io-eap6Apache-commons-lang-eap6Apache-commons-lang-eap6Apache-commons-lang-eap6Apache-commons-pool-eap6Apache-commons-pool-eap6Apache-commons-pool-eap6Apache-mime4jApache-mime4j
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Timeline
2015-01-01
Published
2015-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.052 · p90
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-473 · CWE-327
└ via CAPEC-473 · CWE-327
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
apache-commons-cli-eap6Tracked
apache-commons-cli-eap6Tracked
apache-commons-codec-eap6Tracked
apache-commons-codec-eap6Tracked
apache-commons-configuration-eap6Tracked
apache-commons-configuration-eap6Tracked
apache-commons-daemon-eap6Tracked
apache-commons-daemon-eap6Tracked
apache-commons-daemon-eap6Tracked
apache-commons-io-eap6Tracked
apache-commons-io-eap6Tracked
apache-commons-io-eap6Tracked
apache-commons-lang-eap6Tracked
apache-commons-lang-eap6Tracked
apache-commons-lang-eap6Tracked
apache-commons-pool-eap6Tracked
apache-commons-pool-eap6Tracked
apache-commons-pool-eap6Tracked
apache-mime4jTracked
apache-mime4jTracked
Source databases
DEB
CVE
RED
UBU