CVE-2026-95616
- EPSS 0.29%
- Veröffentlicht 30.09.2026 12:25:28
- Zuletzt bearbeitet 06.10.2026 17:21:33
An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4...
CVE-2026-92899
- EPSS 0.26%
- Veröffentlicht 30.09.2026 12:02:41
- Zuletzt bearbeitet 02.10.2026 20:18:52
Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written as base64 in severa...
CVE-2026-92121
- EPSS 0.35%
- Veröffentlicht 30.09.2026 12:01:55
- Zuletzt bearbeitet 06.10.2026 17:22:23
In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set. The WS-SecurityPolicy enforcer uses that flag to decide whether an element needs checking, ...
CVE-2026-89238
- EPSS 0.21%
- Veröffentlicht 30.09.2026 11:59:09
- Zuletzt bearbeitet 06.10.2026 17:26:05
WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to versions 4.0.2 or 3.0....
CVE-2026-88920
- EPSS 0.53%
- Veröffentlicht 30.09.2026 11:58:00
- Zuletzt bearbeitet 02.10.2026 20:17:49
An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key. Users are...
CVE-2026-87830
- EPSS 0.18%
- Veröffentlicht 30.09.2026 11:57:01
- Zuletzt bearbeitet 06.10.2026 17:26:47
In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the actual XML element path. A remote SOAP peer may therefore send a required element without the expect...
CVE-2026-85532
- EPSS 0.36%
- Veröffentlicht 30.09.2026 11:55:53
- Zuletzt bearbeitet 02.10.2026 20:14:49
Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically weak keys or excessive CPU and memory consumption when processing crafted WS-Security messages. The fixes enforce a...
- EPSS 22.71%
- Veröffentlicht 10.03.2021 08:15:14
- Zuletzt bearbeitet 21.11.2024 05:02:11
An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to u...
CVE-2011-2487
- EPSS 1.76%
- Veröffentlicht 11.03.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 01:28:23
The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.
CVE-2015-0226
- EPSS 5.5%
- Veröffentlicht 30.10.2017 14:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via...