4.3
CVE-2013-2172
- EPSS 5.45%
- Published 20.08.2013 22:55:04
- Last modified 11.04.2025 00:51:21
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to spoof an XML Signature by using the CanonicalizationMethod parameter to specify an arbitrary weak "canonicalization algorithm to apply to the SignedInfo part of the Signature."
Data is provided by the National Vulnerability Database (NVD)
Apache ≫ Santuario Xml Security For Java Version1.4.7
Apache ≫ Santuario Xml Security For Java Version1.5.0
Apache ≫ Santuario Xml Security For Java Version1.5.1
Apache ≫ Santuario Xml Security For Java Version1.5.2
Apache ≫ Santuario Xml Security For Java Version1.5.3
Apache ≫ Santuario Xml Security For Java Version1.5.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 5.45% | 0.897 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|