CVE-2012-5575
published 2013-08-19CVE-2012-5575: Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the…
PriorityP337medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
6.32%
92.8th percentile
Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack."
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_soa_platform | — | — |
| redhat | jboss_enterprise_web_platform | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Inadequate Encryption Strength in Apache CXF
ghsa·2022-05-13
CVE-2012-5575 [MEDIUM] CWE-326 Inadequate Encryption Strength in Apache CXF
Inadequate Encryption Strength in Apache CXF
Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack."
OSV
Inadequate Encryption Strength in Apache CXF
osv·2022-05-13
CVE-2012-5575 [MEDIUM] Inadequate Encryption Strength in Apache CXF
Inadequate Encryption Strength in Apache CXF
Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack."
Red Hat
apache-cxf: XML encryption backwards compatibility attacks
vendor_redhat·2013-03-08·CVSS 6.4
CVE-2012-5575 [MEDIUM] CWE-327 apache-cxf: XML encryption backwards compatibility attacks
apache-cxf: XML encryption backwards compatibility attacks
Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack."
Package: cxf (Red Hat JBoss BRMS 5) - Affected
Package: jbossws-native (Red Hat JBoss BRMS 5) - Affected
Package: jbossws-native (Red Hat JBoss Portal 4) - Affected
Package: jbossws-native (Red Hat JBoss Portal 5) - Affected
Package: cxf (Red Hat JBoss Portal 6) - Affected
Package: jbossws-native (Red Hat JBoss SOA
No detection rules found.
No public exploits indexed.
http://cxf.apache.org/cve-2012-5575.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0833.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0834.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0839.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0873.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0874.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0875.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0876.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0943.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1028.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1143.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1437.htmlhttp://www.nds.ruhr-uni-bochum.de/research/publications/backwards-compatibility/http://www.securityfocus.com/bid/60043https://bugzilla.redhat.com/show_bug.cgi?id=880443https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3Ehttp://cxf.apache.org/cve-2012-5575.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0833.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0834.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0839.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0873.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0874.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0875.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0876.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0943.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1028.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1143.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1437.htmlhttp://www.nds.ruhr-uni-bochum.de/research/publications/backwards-compatibility/http://www.securityfocus.com/bid/60043https://bugzilla.redhat.com/show_bug.cgi?id=880443https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3E
2013-08-19
Published