Severity
6.4MEDIUM
EPSS
9.5%
top 7.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 19
Latest updateMay 13

Description

Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack."

CVSS vector

AV:N/AC:L/C:P/I:P/A:NExploitability: 10.0 | Impact: 4.9

Affected Packages7 packages

🔴Vulnerability Details

3
GHSA
Inadequate Encryption Strength in Apache CXF2022-05-13
OSV
Inadequate Encryption Strength in Apache CXF2022-05-13
CVEList
CVE-2012-5575: Apache CXF 22013-08-19

📋Vendor Advisories

1
Red Hat
apache-cxf: XML encryption backwards compatibility attacks2013-03-08

💬Community

1
Bugzilla
CVE-2012-5575 jbossws-native, jbossws-cxf, apache-cxf: XML encryption backwards compatibility attacks2012-11-27
CVE-2012-5575 (MEDIUM CVSS 6.4) | Apache CXF 2.5.x before 2.5.10 | cvebase.io