CVE-2011-2487
published 2020-03-11CVE-2011-2487: The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.
PriorityP430medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
1.76%
75.4th percentile
The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | 2.4.0 – 2.4.6 | — |
| apache | cxf | 2.5.0 – 2.5.2 | — |
| apache | wss4j | < 1.6.5 | 1.6.5 |
| apache | wss4j | <= 1.6.16 | — |
| apache | wss4j | — | — |
| apache | wss4j | — | — |
| apache | wss4j | — | — |
| apache | wss4j | >= 0 < 1.6.15-2 | 1.6.15-2 |
| apache | wss4j | >= 0 < 1.6.15-2 | 1.6.15-2 |
| apache | wss4j | >= 0 < 1.6.15-2 | 1.6.15-2 |
| apache | wss4j | >= 0 < 1.6.15-2 | 1.6.15-2 |
| debian | wss4j | < wss4j 1.6.15-2 (bookworm) | wss4j 1.6.15-2 (bookworm) |
| redhat | jboss_business_rules_management_system | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_soa_platform | — | — |
| redhat | jboss_enterprise_soa_platform | — | — |
| redhat | jboss_enterprise_web_platform | — | — |
| redhat | jboss_portal | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
ghsa5.9MEDIUM
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J
ghsa·2022-05-14·CVSS 5.9
CVE-2015-0226 [MEDIUM] CWE-327 Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J
Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J
Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series of crafted messages. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-2487.
OSV
Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J
osv·2022-05-14·CVSS 5.9
CVE-2015-0226 [MEDIUM] Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J
Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J
Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series of crafted messages. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-2487.
OSV
Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J
osv·2022-04-22
CVE-2011-2487 [MEDIUM] Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J
Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J
The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.
GHSA
Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J
ghsa·2022-04-22
CVE-2011-2487 [MEDIUM] CWE-327 Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J
Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J
The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.
OSV
CVE-2015-0226: Apache WSS4J before 1
osv·2017-10-30·CVSS 5.9
CVE-2015-0226 [MEDIUM] CVE-2015-0226: Apache WSS4J before 1
Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series of crafted messages. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-2487.
Red Hat
wss4j: Apache WSS4J is vulnerable to Bleichenbacher's attack (incomplete fix for CVE-2011-2487)
vendor_redhat·2015-02-10·CVSS 5.9
CVE-2015-0226 [MEDIUM] CWE-327 wss4j: Apache WSS4J is vulnerable to Bleichenbacher's attack (incomplete fix for CVE-2011-2487)
wss4j: Apache WSS4J is vulnerable to Bleichenbacher's attack (incomplete fix for CVE-2011-2487)
Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series of crafted messages. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-2487.
It was found that a prior countermeasure in Apache WSS4J for Bleichenbacher's attack on XML Encryption (CVE-2011-2487) threw an exception that permitted an attacker to determine the failure of the attempted attack, thereby leaving WSS4J vulnerable to the attack. The original flaw allowed a remote attacker to recover the entire plain text f
Debian
CVE-2015-0226: wss4j - Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information a...
vendor_debian·2015·CVSS 5.9
CVE-2015-0226 [MEDIUM] CVE-2015-0226: wss4j - Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information a...
Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series of crafted messages. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-2487.
Scope: local
bookworm: resolved (fixed in 1.6.15-2)
bullseye: resolved (fixed in 1.6.15-2)
forky: resolved (fixed in 1.6.15-2)
sid: resolved (fixed in 1.6.15-2)
trixie: resolved (fixed in 1.6.15-2)
Red Hat
jbossws: Prone to Bleichenbacher attack against to be distributed symmetric key
vendor_redhat·2012-09-04·CVSS 5.9
CVE-2011-2487 [MEDIUM] CWE-327 jbossws: Prone to Bleichenbacher attack against to be distributed symmetric key
jbossws: Prone to Bleichenbacher attack against to be distributed symmetric key
The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.
A flaw was found in JBoss web services where the services used a weak symmetric encryption protocol, PKCS#1 v1.5. An attacker could use this weakness in chosen-ciphertext attacks to recover the symmetric key and conduct further attacks.
Statement: This flaw affects Apache CXF (WSS4J) and jbossws-native as shipped with various JBoss products. It does not affect JBoss Enterprise Application Platform 6 and JBoss Application Server 7.1.1 and above. These products include WSS4J 1.6.5, which incorporates a fix for this flaw. On affected products, this flaw
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-0226 wss4j: Apache WSS4J is vulnerable to Bleichenbacher's attack (incomplete fix for CVE-2011-2487)
bugzilla·2015-02-11·CVSS 5.9
CVE-2015-0226 [MEDIUM] CVE-2015-0226 wss4j: Apache WSS4J is vulnerable to Bleichenbacher's attack (incomplete fix for CVE-2011-2487)
CVE-2015-0226 wss4j: Apache WSS4J is vulnerable to Bleichenbacher's attack (incomplete fix for CVE-2011-2487)
Apache WSS4J 1.6.5 contained a countermeasure for Bleichenbacher's attack on XML Encryption, where the PKCS#1 v1.5 Key Transport Algorithm is used to encrypt symmetric keys as part of WS-Security. In particular, the fix avoided leaking information on whether decryption failed when decrypting the encrypted key or decrypting the message data.
However, it is still possible to craft a message such that an attacker can tell where the decryption failure took place, and hence WSS4J is vulnerable to the original attack.
See here for more information on the original fix for WSS4J 1.6.5:
http://cxf.apache.org/note-on-cve-2011-2487.html
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011
Bugzilla
CVE-2012-5575 jbossws-native, jbossws-cxf, apache-cxf: XML encryption backwards compatibility attacks
bugzilla·2012-11-27·CVSS 5.0
CVE-2012-5575 [MEDIUM] CVE-2012-5575 jbossws-native, jbossws-cxf, apache-cxf: XML encryption backwards compatibility attacks
CVE-2012-5575 jbossws-native, jbossws-cxf, apache-cxf: XML encryption backwards compatibility attacks
Tibor Jager, Kenneth G. Paterson and Juraj Somorovsky have described XML encryption backwards compatibility attacks against various frameworks, including Apache CXF. An attacker can use these flaws to force a server to utilize insecure, legacy cryptosystems when secure cryptosystems are enabled on endpoints. This could expose flaws in the underlying legacy cryptosystems, such as CVE-2011-1096 and CVE-2011-2487. This flaw also affects the jbossws-native stack.
Discussion:
External References:
http://www.nds.ruhr-uni-bochum.de/research/publications/backwards-compatibility/
http://cxf.apache.org/cve-2012-5575.html
---
This issue has been addressed in following products:
JBoss Enterpris
Bugzilla
CVE-2011-2487 jbossws: Prone to Bleichenbacher attack against to be distributed symmetric key
bugzilla·2011-06-15·CVSS 5.9
CVE-2011-2487 [MEDIUM] CVE-2011-2487 jbossws: Prone to Bleichenbacher attack against to be distributed symmetric key
CVE-2011-2487 jbossws: Prone to Bleichenbacher attack against to be distributed symmetric key
It was found that JBossWS, a J2EE Web Services server, leaked further
channel data, by using PKCS#1 v1.5 protocol family / public key encryption
scheme in order to distribute the symmetric key. A remote attacker, aware
of a cryptographic weakness of the PKCS#1 v1.5 public key encryption scheme,
could use this flaw to conduct chosen-encrypted-key attacks, leading to the
recovery of the entire plaintext form of the intended symmetric key, to be
distributed, by examining of the differences between SOAP responses, sent
from JBossWS server.
Acknowledgements:
Red Hat would like to thank Juraj Somorovsky of Ruhr-University Bochum
for reporting this issue.
Discussion:
The CVE identifier of CVE-2011-2
http://cxf.apache.org/note-on-cve-2011-2487.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0191.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0192.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0193.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0194.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0195.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0196.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0198.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0221.htmlhttp://www.securityfocus.com/bid/57549https://bugzilla.redhat.com/show_bug.cgi?id=713539https://exchange.xforce.ibmcloud.com/vulnerabilities/81737https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3Ehttps://www.nds.ruhr-uni-bochum.de/research/publications/breaking-xml-encryption-pkcs15/http://cxf.apache.org/note-on-cve-2011-2487.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0191.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0192.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0193.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0194.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0195.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0196.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0198.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0221.htmlhttp://www.securityfocus.com/bid/57549https://bugzilla.redhat.com/show_bug.cgi?id=713539https://exchange.xforce.ibmcloud.com/vulnerabilities/81737https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3Ehttps://www.nds.ruhr-uni-bochum.de/research/publications/breaking-xml-encryption-pkcs15/
2020-03-11
Published