CVE-2013-5960
published 2013-09-30CVE-2013-5960: The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ESAPI) for Java 2.x before 2.1.0.1 does…
PriorityP431medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
1.65%
74.1th percentile
The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ESAPI) for Java 2.x before 2.1.0.1 does not properly resist tampering with serialized ciphertext, which makes it easier for remote attackers to bypass intended cryptographic protection mechanisms via an attack against the intended cipher mode in a non-default configuration, a different vulnerability than CVE-2013-5679.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| owasp | enterprise_security_api | >= 2.0 < 2.1.0.1 | 2.1.0.1 |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
ghsa2.6LOW
osv2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Missing Cryptographic Step in OWASP Enterprise Security API for Java
osv·2022-05-14·CVSS 2.6
CVE-2013-5960 [LOW] Missing Cryptographic Step in OWASP Enterprise Security API for Java
Missing Cryptographic Step in OWASP Enterprise Security API for Java
The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ESAPI) for Java 2.x before 2.1.0.1 does not properly resist tampering with serialized ciphertext, which makes it easier for remote attackers to bypass intended cryptographic protection mechanisms via an attack against the intended cipher mode in a non-default configuration, a different vulnerability than CVE-2013-5679.
GHSA
Missing Cryptographic Step in OWASP Enterprise Security API for Java
ghsa·2022-05-14·CVSS 2.6
CVE-2013-5960 [LOW] CWE-325 Missing Cryptographic Step in OWASP Enterprise Security API for Java
Missing Cryptographic Step in OWASP Enterprise Security API for Java
The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ESAPI) for Java 2.x before 2.1.0.1 does not properly resist tampering with serialized ciphertext, which makes it easier for remote attackers to bypass intended cryptographic protection mechanisms via an attack against the intended cipher mode in a non-default configuration, a different vulnerability than CVE-2013-5679.
Cisco
Portable SDK for UPnP Devices Contains Buffer Overflow Vulnerabilities
vendor_cisco
CVE-2012-5960 Portable SDK for UPnP Devices Contains Buffer Overflow Vulnerabilities
CVE-2012-5960: Portable SDK for UPnP Devices Contains Buffer Overflow Vulnerabilities
The Portable Software Developer Kit (SDK) for Universal Plug-n-Play (UPnP) Devices contains a libupnp library, originally known as the Intel SDK for UPnP Devices, which is vulnerable to multiple stack-based buffer overflows when handling malicious Simple Service Discovery Protocol (SSDP) requests. This library is used in several vendor network devices, in addition to media streaming and file sharing applications. These vulnerabilities were disclosed on January 29th, 2013 in a CERT Vulnerability Note, VU#922681, which can be viewed at http://www.kb.cert.org/vuls/id/922681 . Cisco is currently evaluating products for possible exposure to these vulnerabilities. This advisory is available at the following lin
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-5679 CVE-2013-5960 owasp-esapi-java: symmetric encryption MAC bypass
bugzilla·2013-09-30·CVSS 2.6
CVE-2013-5679 [LOW] CVE-2013-5679 CVE-2013-5960 owasp-esapi-java: symmetric encryption MAC bypass
CVE-2013-5679 CVE-2013-5960 owasp-esapi-java: symmetric encryption MAC bypass
Owasp-Esapi-Java, a free, open source, web application security control library, was found to have a vulnerability, where it was possible to bypass the authenticity check by setting the MAC length to 0 and the MAC to null, when ESAPI symmetric crypto with CBC mode is used with PKCS#7 padding (called PKCS5Padding in Java), and an HMAC for authenticity.
The configuration could result in an exploitable vulnerability depending on the context for encryption and what degree an attacker can tamper with the serialized ciphertext, though only some ESAPI were found to be exploitable when using the default configuration. To be exploitable, an attacker would require the ability to modify ciphertext either at rest or in tra
arXiv
Evaluating LLMs for One-Shot Patching of Real and Artificial Vulnerabilities
arxiv_fulltext·2025-11-28
Evaluating LLMs for One-Shot Patching of Real and Artificial Vulnerabilities
Evaluating LLMs for One-Shot Patching of Real and Artificial Vulnerabilities
Aayush Garg
[email protected]
0000-0002-2507-8846
Luxembourg Institute of Science and Technology
Luxembourg
Zanis Ali Khan
[email protected]
0000-0002-3935-2148
Luxembourg Institute of Science and Technology
Luxembourg
Renzo Degiovanni
[email protected]
0000-0003-1611-3969
Luxembourg Institute of Science and Technology
Luxembourg
Qiang Tang
[email protected]
0000-0002-6153-4255
Luxembourg Institute of Science and Technology
Luxembourg
## Abstract
Automated vulnerability patching is crucial for software security, and recent advancements in Large Language Models (LLMs) present promising capabilities for automating this task. However, existing research has primarily assessed LLMs using public
http://code.google.com/p/owasp-esapi-java/issues/detail?id=306http://lists.owasp.org/pipermail/esapi-dev/2013-August/002285.htmlhttp://owasp-esapi-java.googlecode.com/svn/trunk/documentation/ESAPI-security-bulletin1.pdfhttp://www.securityfocus.com/bid/62415https://github.com/ESAPI/esapi-java-legacy/blob/master/documentation/esapi4java-core-2.1.0.1-release-notes.txthttps://github.com/ESAPI/esapi-java-legacy/issues/359https://github.com/esapi/esapi-java-legacy/issues/306http://code.google.com/p/owasp-esapi-java/issues/detail?id=306http://lists.owasp.org/pipermail/esapi-dev/2013-August/002285.htmlhttp://owasp-esapi-java.googlecode.com/svn/trunk/documentation/ESAPI-security-bulletin1.pdfhttp://www.securityfocus.com/bid/62415https://github.com/ESAPI/esapi-java-legacy/blob/master/documentation/esapi4java-core-2.1.0.1-release-notes.txthttps://github.com/ESAPI/esapi-java-legacy/issues/359https://github.com/esapi/esapi-java-legacy/issues/306
2013-09-30
Published