CVE-2009-0217

The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
certccCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
VendorProductVersion
ibmwebsphere_application_server
6.0
ibmwebsphere_application_server
6.0.0.1
ibmwebsphere_application_server
6.0.0.2
ibmwebsphere_application_server
6.0.0.3
ibmwebsphere_application_server
6.0.1
ibmwebsphere_application_server
6.0.1.1
ibmwebsphere_application_server
6.0.1.2
ibmwebsphere_application_server
6.0.1.3
ibmwebsphere_application_server
6.0.1.5
ibmwebsphere_application_server
6.0.1.7
ibmwebsphere_application_server
6.0.1.9
ibmwebsphere_application_server
6.0.1.11
ibmwebsphere_application_server
6.0.1.13
ibmwebsphere_application_server
6.0.1.15
ibmwebsphere_application_server
6.0.1.17
ibmwebsphere_application_server
6.0.2
ibmwebsphere_application_server
6.0.2
ibmwebsphere_application_server
6.0.2.1
ibmwebsphere_application_server
6.0.2.2
ibmwebsphere_application_server
6.0.2.3
ibmwebsphere_application_server
6.0.2.10
ibmwebsphere_application_server
6.0.2.11
ibmwebsphere_application_server
6.0.2.12
ibmwebsphere_application_server
6.0.2.13
ibmwebsphere_application_server
6.0.2.14
ibmwebsphere_application_server
6.0.2.15
ibmwebsphere_application_server
6.0.2.16
ibmwebsphere_application_server
6.0.2.17
ibmwebsphere_application_server
6.0.2.18
ibmwebsphere_application_server
6.0.2.19
ibmwebsphere_application_server
6.0.2.20
ibmwebsphere_application_server
6.0.2.21
ibmwebsphere_application_server
6.0.2.22
ibmwebsphere_application_server
6.0.2.23
ibmwebsphere_application_server
6.0.2.24
ibmwebsphere_application_server
6.0.2.25
ibmwebsphere_application_server
6.0.2.28
ibmwebsphere_application_server
6.0.2.29
ibmwebsphere_application_server
6.0.2.30
ibmwebsphere_application_server
6.0.2.31
ibmwebsphere_application_server
6.0.2.32
ibmwebsphere_application_server
6.0.2.33
ibmwebsphere_application_server
6.1
ibmwebsphere_application_server
6.1.0
ibmwebsphere_application_server
6.1.0.0
ibmwebsphere_application_server
6.1.0.1
ibmwebsphere_application_server
6.1.0.2
ibmwebsphere_application_server
6.1.0.3
ibmwebsphere_application_server
6.1.0.4
ibmwebsphere_application_server
6.1.0.5
ibmwebsphere_application_server
6.1.0.6
ibmwebsphere_application_server
6.1.0.7
ibmwebsphere_application_server
6.1.0.8
ibmwebsphere_application_server
6.1.0.9
ibmwebsphere_application_server
6.1.0.10
ibmwebsphere_application_server
6.1.0.11
ibmwebsphere_application_server
6.1.0.12
ibmwebsphere_application_server
6.1.0.13
ibmwebsphere_application_server
6.1.0.14
ibmwebsphere_application_server
6.1.0.15
ibmwebsphere_application_server
6.1.0.16
ibmwebsphere_application_server
6.1.0.17
ibmwebsphere_application_server
6.1.0.18
ibmwebsphere_application_server
6.1.0.19
ibmwebsphere_application_server
6.1.0.20
ibmwebsphere_application_server
6.1.0.21
ibmwebsphere_application_server
6.1.0.22
ibmwebsphere_application_server
6.1.0.23
ibmwebsphere_application_server
7.0
ibmwebsphere_application_server
7.0.0.1
mono_projectmono
1.2.1
mono_projectmono
1.2.2
mono_projectmono
1.2.3
mono_projectmono
1.2.4
mono_projectmono
1.2.5
mono_projectmono
1.2.6
mono_projectmono
1.9
mono_projectmono
2.0
oracleapplication_server
10.1.2.3
oracleapplication_server
10.1.3.4
oracleapplication_server
10.1.4.3im:im
oraclebea_product_suite
8.1:sp6
oraclebea_product_suite
9.0
oraclebea_product_suite
9.1
oraclebea_product_suite
9.2:mp3
oraclebea_product_suite
10.0:mp1
oraclebea_product_suite
10.3
oracleweblogic_server_component
8.1:sp6
oracleweblogic_server_component
9.0
oracleweblogic_server_component
9.1
oracleweblogic_server_component
9.2:mp3
oracleweblogic_server_component
10.0:mp1
oracleweblogic_server_component
10.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
mono
bullseye
6.8.0.105+dfsg-3.3~deb11u1
fixed
lenny
no-dsa
bookworm
6.8.0.105+dfsg-3.3
fixed
sid
6.12.0.199+dfsg-2
fixed
trixie
6.12.0.199+dfsg-2
fixed
xml-security-c
bullseye
2.0.2-4
fixed
lenny
no-dsa
bookworm
2.0.4-2
fixed
sid
2.0.4-2
fixed
trixie
2.0.4-2
fixed
xmlsec1
bullseye
1.2.31-1
fixed
lenny
no-dsa
bookworm
1.2.37-2
fixed
sid
1.2.41-1
fixed
trixie
1.2.41-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libreoffice
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
not-affected
maverick
dne
lucid
dne
karmic
dne
jaunty
dne
intrepid
dne
hardy
dne
dapper
dne
libxml-security-java
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
not-affected
jaunty
ignored
intrepid
ignored
hardy
dne
dapper
dne
mono
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
not-affected
jaunty
Fixed 2.0.1-4ubuntu0.1
released
intrepid
Fixed 1.9.1+dfsg-4ubuntu2.1
released
hardy
Fixed 1.2.6+dfsg-6ubuntu3.1
released
dapper
ignored
openjdk-6
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
not-affected
jaunty
Fixed 6b14-1.4.1-0ubuntu11
released
intrepid
Fixed 6b12-0ubuntu6.5
released
hardy
Fixed 6b18-1.8.2-4ubuntu1~8.04.1
released
dapper
dne
openoffice.org
saucy
dne
raring
dne
quantal
dne
precise
not-affected
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
Fixed 1:3.1.1-5ubuntu1.1
released
jaunty
Fixed 1:3.0.1-9ubuntu3.2
released
intrepid
Fixed 1:2.4.1-11ubuntu2.3
released
hardy
Fixed 1:2.4.1-1ubuntu2.3
released
dapper
ignored
xml-security-c
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
not-affected
jaunty
Fixed 1.4.0-3+lenny2build0.9.04.1
released
intrepid
ignored
hardy
ignored
dapper
dne
xmlsec1
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
ignored
karmic
ignored
jaunty
ignored
intrepid
ignored
hardy
ignored
dapper
ignored
References