Apache

Wss4j

12 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 7.54%
  • Veröffentlicht 12.02.2015 16:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks."

  • EPSS 9.22%
  • Veröffentlicht 30.10.2014 14:55:07
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation method security semantics, which allows remote atta...