Vulnerability Database

296,746

Total vulnerabilities in the database

CVE-2012-2378

Apache CXF 2.4.5 through 2.4.7, 2.5.1 through 2.5.3, and 2.6.x before 2.6.1, does not properly enforce child policies of a WS-SecurityPolicy 1.1 SupportingToken policy on the client side, which allows remote attackers to bypass the (1) AlgorithmSuite, (2) SignedParts, (3) SignedElements, (4) EncryptedParts, and (5) EncryptedElements policies.

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:P/I:N/A:N
Software From Fixed in
apache / cxf 2.4.6 2.4.6.x
apache / cxf 2.4.7 2.4.7.x
apache / cxf 2.4.5 2.4.5.x
apache / cxf 2.5.2 2.5.2.x
apache / cxf 2.5.3 2.5.3.x
apache / cxf 2.5.1 2.5.1.x
apache / cxf 2.6.0 2.6.0.x
Maven icon org.apache.cxf / cxf 2.4.5 2.4.8
Maven icon org.apache.cxf / cxf 2.5.1 2.5.3
Maven icon org.apache.cxf / cxf 2.6.0 2.6.1