CVE-2012-2379

EUVD-2022-1980
Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and attack vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
Affected Products (NVD)
VendorProductVersion
apachecxf
2.4.0
apachecxf
2.4.1
apachecxf
2.4.2
apachecxf
2.4.3
apachecxf
2.4.4
apachecxf
2.4.5
apachecxf
2.4.6
apachecxf
2.4.7
apachecxf
2.5.0
apachecxf
2.5.1
apachecxf
2.5.2
apachecxf
2.5.3
apachecxf
2.6.0
𝑥
= Vulnerable software versions
References