CVE-2011-2487
11.03.2020, 16:15
The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.Enginsight
Vendor | Product | Version |
---|---|---|
apache | cxf | 2.4.0 ≤ 𝑥 ≤ 2.4.6 |
apache | cxf | 2.5.0 ≤ 𝑥 ≤ 2.5.2 |
apache | wss4j | 𝑥 < 1.6.5 |
redhat | jboss_business_rules_management_system | 5.3 |
redhat | jboss_enterprise_application_platform | 5.0.0 |
redhat | jboss_enterprise_application_platform_text-only_advisories | - |
redhat | jboss_enterprise_soa_platform | 4.2.0 |
redhat | jboss_enterprise_soa_platform | 4.3.0 |
redhat | jboss_enterprise_web_platform | 5.0.0 |
redhat | jboss_middleware_text-only_advisories | - |
redhat | jboss_portal | 4.0.0 |
redhat | jboss_web_services | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References