CVE-2011-2487

The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
VendorProductVersion
apachecxf
2.4.0 ≤
𝑥
≤ 2.4.6
apachecxf
2.5.0 ≤
𝑥
≤ 2.5.2
apachewss4j
𝑥
< 1.6.5
redhatjboss_business_rules_management_system
5.3
redhatjboss_enterprise_application_platform
5.0.0
redhatjboss_enterprise_application_platform_text-only_advisories
-
redhatjboss_enterprise_soa_platform
4.2.0
redhatjboss_enterprise_soa_platform
4.3.0
redhatjboss_enterprise_web_platform
5.0.0
redhatjboss_middleware_text-only_advisories
-
redhatjboss_portal
4.0.0
redhatjboss_web_services
-
𝑥
= Vulnerable software versions
References