The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.
2020-03-11T16:15:11.773
2024-11-21T01:28:23.107
Modified
CVSSv3.1: 5.9 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:N/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | cxf | ≤ 2.4.6 | Yes |
Application | apache | cxf | ≤ 2.5.2 | Yes |
Application | apache | wss4j | < 1.6.5 | Yes |
Application | redhat | jboss_business_rules_management_system | 5.3 | Yes |
Application | redhat | jboss_enterprise_application_platform | 5.0.0 | Yes |
Application | redhat | jboss_enterprise_application_platform_text-only_advisories | - | Yes |
Application | redhat | jboss_enterprise_soa_platform | 4.2.0 | Yes |
Application | redhat | jboss_enterprise_soa_platform | 4.3.0 | Yes |
Application | redhat | jboss_enterprise_web_platform | 5.0.0 | Yes |
Application | redhat | jboss_middleware_text-only_advisories | - | Yes |
Application | redhat | jboss_portal | 4.0.0 | Yes |
Application | redhat | jboss_web_services | - | Yes |