CVE-2011-1096
published 2012-11-23CVE-2011-1096: The W3C XML Encryption Standard, as used in the JBoss Web Services (JBossWS) component in JBoss Enterprise Portal Platform before 5.2.2 and other products…
PriorityP425medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.59%
83.5th percentile
The W3C XML Encryption Standard, as used in the JBoss Web Services (JBossWS) component in JBoss Enterprise Portal Platform before 5.2.2 and other products, when using block ciphers in cipher-block chaining (CBC) mode, allows remote attackers to obtain plaintext data via a chosen-ciphertext attack on SOAP responses, aka "character encoding pattern attack."
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_portal_platform | <= 5.2.1 | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
jbossws: Prone to character encoding pattern attack (XML Encryption flaw)
vendor_redhat·2011-10-19·CVSS 5.0
CVE-2011-1096 [MEDIUM] CWE-327 jbossws: Prone to character encoding pattern attack (XML Encryption flaw)
jbossws: Prone to character encoding pattern attack (XML Encryption flaw)
The W3C XML Encryption Standard, as used in the JBoss Web Services (JBossWS) component in JBoss Enterprise Portal Platform before 5.2.2 and other products, when using block ciphers in cipher-block chaining (CBC) mode, allows remote attackers to obtain plaintext data via a chosen-ciphertext attack on SOAP responses, aka "character encoding pattern attack."
Package: Security (Red Hat JBoss BRMS 5) - Affected
Package: cxf (Red Hat JBoss Portal 5) - Affected
Package: cxf (Red Hat JBoss SOA Platform 5) - Affected
GHSA
GHSA-r89h-jcj8-5p2m: The W3C XML Encryption Standard, as used in the JBoss Web Services (JBossWS) component in JBoss Enterprise Portal Platform before 5
ghsa_unreviewed·2022-05-13
CVE-2011-1096 [MEDIUM] GHSA-r89h-jcj8-5p2m: The W3C XML Encryption Standard, as used in the JBoss Web Services (JBossWS) component in JBoss Enterprise Portal Platform before 5
The W3C XML Encryption Standard, as used in the JBoss Web Services (JBossWS) component in JBoss Enterprise Portal Platform before 5.2.2 and other products, when using block ciphers in cipher-block chaining (CBC) mode, allows remote attackers to obtain plaintext data via a chosen-ciphertext attack on SOAP responses, aka "character encoding pattern attack."
No detection rules found.
Bugzilla
CVE-2012-5575 jbossws-native, jbossws-cxf, apache-cxf: XML encryption backwards compatibility attacks
bugzilla·2012-11-27·CVSS 5.0
CVE-2012-5575 [MEDIUM] CVE-2012-5575 jbossws-native, jbossws-cxf, apache-cxf: XML encryption backwards compatibility attacks
CVE-2012-5575 jbossws-native, jbossws-cxf, apache-cxf: XML encryption backwards compatibility attacks
Tibor Jager, Kenneth G. Paterson and Juraj Somorovsky have described XML encryption backwards compatibility attacks against various frameworks, including Apache CXF. An attacker can use these flaws to force a server to utilize insecure, legacy cryptosystems when secure cryptosystems are enabled on endpoints. This could expose flaws in the underlying legacy cryptosystems, such as CVE-2011-1096 and CVE-2011-2487. This flaw also affects the jbossws-native stack.
Discussion:
External References:
http://www.nds.ruhr-uni-bochum.de/research/publications/backwards-compatibility/
http://cxf.apache.org/cve-2012-5575.html
---
This issue has been addressed in following products:
JBoss Enterpris
Bugzilla
CVE-2011-1096 jbossws: Prone to character encoding pattern attack (XML Encryption flaw)
bugzilla·2011-03-03·CVSS 5.0
CVE-2011-1096 [MEDIUM] CVE-2011-1096 jbossws: Prone to character encoding pattern attack (XML Encryption flaw)
CVE-2011-1096 jbossws: Prone to character encoding pattern attack (XML Encryption flaw)
Tibor Jager, Juraj Somorovsky, Meiko Jensen, and Jorg Schwenk
described an attack technique against W3C XML Encryption Standard,
when the block ciphers were used in cipher-block chaining (CBC)
mode of operation. A remote attacker, aware of a cryptographic
weakness of the CBC mode could use this flaw to conduct
chosen-ciphertext attacks, leading to the recovery of the entire
plaintext of a particular cryptogram by examining of the differences
between SOAP responses, sent from JBossWS, J2EE Web Services server.
Acknowledgements:
Red Hat would like to thank Juraj Somorovsky of Ruhr-University Bochum
for reporting this issue.
Discussion:
The CVE identifier of CVE-2011-1096 has been assigned to this iss
http://aktuell.ruhr-uni-bochum.de/pm2011/pm00330.html.dehttp://coheigea.blogspot.com/2012/04/note-on-cve-2011-1096.htmlhttp://cxf.apache.org/note-on-cve-2011-1096.htmlhttp://dl.acm.org/citation.cfm?id=2046756&dl=ACM&coll=DLhttp://rhn.redhat.com/errata/RHSA-2012-1301.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1330.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1344.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0191.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0192.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0193.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0194.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0195.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0196.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0197.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0198.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0221.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0261.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1437.htmlhttp://secunia.com/advisories/51984http://secunia.com/advisories/52054http://www.csoonline.com/article/692366/widely-used-encryption-standard-is-insecure-say-expertshttp://www.securityfocus.com/bid/55770https://bugzilla.redhat.com/show_bug.cgi?id=681916https://exchange.xforce.ibmcloud.com/vulnerabilities/79031https://lists.apache.org/thread.html/8d5d29747548a24cccdb7f3e2d4d599ffb7ffe4537426b3c9a852cf4%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3Ehttp://aktuell.ruhr-uni-bochum.de/pm2011/pm00330.html.dehttp://coheigea.blogspot.com/2012/04/note-on-cve-2011-1096.htmlhttp://cxf.apache.org/note-on-cve-2011-1096.htmlhttp://dl.acm.org/citation.cfm?id=2046756&dl=ACM&coll=DLhttp://rhn.redhat.com/errata/RHSA-2012-1301.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1330.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1344.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0191.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0192.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0193.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0194.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0195.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0196.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0197.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0198.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0221.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0261.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1437.htmlhttp://secunia.com/advisories/51984http://secunia.com/advisories/52054http://www.csoonline.com/article/692366/widely-used-encryption-standard-is-insecure-say-expertshttp://www.securityfocus.com/bid/55770https://bugzilla.redhat.com/show_bug.cgi?id=681916https://exchange.xforce.ibmcloud.com/vulnerabilities/79031https://lists.apache.org/thread.html/8d5d29747548a24cccdb7f3e2d4d599ffb7ffe4537426b3c9a852cf4%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3E
2012-11-23
Published