CVE-2011-1096

Severity
5.0MEDIUM
EPSS
1.2%
top 21.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 23
Latest updateMay 13

Description

The W3C XML Encryption Standard, as used in the JBoss Web Services (JBossWS) component in JBoss Enterprise Portal Platform before 5.2.2 and other products, when using block ciphers in cipher-block chaining (CBC) mode, allows remote attackers to obtain plaintext data via a chosen-ciphertext attack on SOAP responses, aka "character encoding pattern attack."

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-r89h-jcj8-5p2m: The W3C XML Encryption Standard, as used in the JBoss Web Services (JBossWS) component in JBoss Enterprise Portal Platform before 52022-05-13
CVEList
CVE-2011-1096: The W3C XML Encryption Standard, as used in the JBoss Web Services (JBossWS) component in JBoss Enterprise Portal Platform before 52012-11-23

💥Exploits & PoCs

1
Exploit-DB
GNOME NetworkManager 0.x - Local Arbitrary File Access2012-02-29

📋Vendor Advisories

1
Red Hat
jbossws: Prone to character encoding pattern attack (XML Encryption flaw)2011-10-19

💬Community

2
Bugzilla
CVE-2012-5575 jbossws-native, jbossws-cxf, apache-cxf: XML encryption backwards compatibility attacks2012-11-27
Bugzilla
CVE-2011-1096 jbossws: Prone to character encoding pattern attack (XML Encryption flaw)2011-03-03
CVE-2011-1096 (MEDIUM CVSS 5) | The W3C XML Encryption Standard | cvebase.io