CVE-2015-0227
published 2015-02-12CVE-2015-0227: Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to…
PriorityP339medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
7.54%
93.8th percentile
Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks."
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | wss4j | <= 1.6.16 | — |
| apache | wss4j | — | — |
| apache | wss4j | — | — |
| apache | wss4j | >= 0 < 1.6.15-2 | 1.6.15-2 |
| apache | wss4j | >= 0 < 1.6.15-2 | 1.6.15-2 |
| apache | wss4j | >= 0 < 1.6.15-2 | 1.6.15-2 |
| apache | wss4j | >= 0 < 1.6.15-2 | 1.6.15-2 |
| debian | wss4j | < wss4j 1.6.15-2 (bookworm) | wss4j 1.6.15-2 (bookworm) |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_apache6.4LOW
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Access Control in Apache WSS4J
ghsa·2022-05-14
CVE-2015-0227 [MEDIUM] CWE-284 Improper Access Control in Apache WSS4J
Improper Access Control in Apache WSS4J
Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks."
OSV
Improper Access Control in Apache WSS4J
osv·2022-05-14
CVE-2015-0227 [MEDIUM] Improper Access Control in Apache WSS4J
Improper Access Control in Apache WSS4J
Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks."
OSV
CVE-2015-0227: Apache WSS4J before 1
osv·2015-02-12·CVSS 5.0
CVE-2015-0227 [MEDIUM] CVE-2015-0227: Apache WSS4J before 1
Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks."
Red Hat
wss4j: Apache WSS4J doesn't correctly enforce the requireSignedEncryptedDataElements property
vendor_redhat·2015-02-10·CVSS 5.0
CVE-2015-0227 [MEDIUM] CWE-358 wss4j: Apache WSS4J doesn't correctly enforce the requireSignedEncryptedDataElements property
wss4j: Apache WSS4J doesn't correctly enforce the requireSignedEncryptedDataElements property
Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks."
It was found that Apache WSS4J permitted bypass of the requireSignedEncryptedDataElements configuration property via XML Signature wrapping attacks. A remote attacker could use this flaw to modify the contents of a signed request.
Package: wss4j (Red Hat BPM Suite 6) - Affected
Package: wss4j (Red Hat JBoss BRMS 5) - Will not fix
Package: wss4j (Red Hat JBoss BRMS 6) - Affected
Package: wss4j (Red Hat JBoss Data Virtualization 6) - Affected
Package: wss4j (Red Hat JBoss Enterprise Application Platform 5) - Will no
Debian
CVE-2015-0227: wss4j - Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypas...
vendor_debian·2015·CVSS 5.0
CVE-2015-0227 [MEDIUM] CVE-2015-0227: wss4j - Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypas...
Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks."
Scope: local
bookworm: resolved (fixed in 1.6.15-2)
bullseye: resolved (fixed in 1.6.15-2)
forky: resolved (fixed in 1.6.15-2)
sid: resolved (fixed in 1.6.15-2)
trixie: resolved (fixed in 1.6.15-2)
Apache
Apache tomcat: CVE-2014-0227
vendor_apache·CVSS 6.4
CVE-2014-0227 [LOW] Apache tomcat: CVE-2014-0227
Apache tomcat: CVE-2014-0227
It was possible to craft a malformed chunk as part of a chunked request that caused Tomcat to read part of the request body as a new request. This was fixed in revisions 1600984 , 1601329 , 1601330 and 1601332 . This issue was identified by the Tomcat security team on 30 May 2014 and made public on 9 February 2015. Affects: 8.0.0-RC1 to 8.0.8 Low: Denial of Service
Severity: low
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-0227 wss4j: Apache WSS4J doesn't correctly enforce the requireSignedEncryptedDataElements property
bugzilla·2015-02-11·CVSS 5.0
CVE-2015-0227 [MEDIUM] CVE-2015-0227 wss4j: Apache WSS4J doesn't correctly enforce the requireSignedEncryptedDataElements property
CVE-2015-0227 wss4j: Apache WSS4J doesn't correctly enforce the requireSignedEncryptedDataElements property
Apache WSS4J has a "requireSignedEncryptedDataElements" boolean configuration property, which if set enforces that EncryptedData elements are in a signed subtree of the document. The default value of this property is "false".
However, it is possible to circumvent this setting by various types of wrapping attacks.
This has been fixed in revision:
http://svn.apache.org/viewvc?view=revision&revision=1619359
Discussion:
Created wss4j tracking bugs for this issue:
Affects: fedora-all [bug 1191455]
---
This issue has been addressed in the following products:
Red Hat JBoss Data Grid 6.4
Via RHSA-2015:0773 https://rhn.redhat.com/errata/RHSA-2015-0773.html
---
This issue has been
Bugzilla
CVE-2015-0227 CVE-2015-0226 wss4j: various flaws [fedora-all]
bugzilla·2015-02-11·CVSS 7.5
CVE-2015-0227 [HIGH] CVE-2015-0227 CVE-2015-0226 wss4j: various flaws [fedora-all]
CVE-2015-0227 CVE-2015-0226 wss4j: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While on
http://rhn.redhat.com/errata/RHSA-2015-0773.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0846.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0847.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0848.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0849.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1176.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1177.htmlhttp://ws.apache.org/wss4j/advisories/CVE-2015-0227.txt.aschttp://www.securityfocus.com/bid/72557https://exchange.xforce.ibmcloud.com/vulnerabilities/100837https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03900en_ushttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0773.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0846.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0847.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0848.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0849.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1176.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1177.htmlhttp://ws.apache.org/wss4j/advisories/CVE-2015-0227.txt.aschttp://www.securityfocus.com/bid/72557https://exchange.xforce.ibmcloud.com/vulnerabilities/100837https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03900en_ushttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
2015-02-12
Published