CVE-2012-2379

Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and attack vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
VendorProductVersion
apachecxf
2.4.0
apachecxf
2.4.1
apachecxf
2.4.2
apachecxf
2.4.3
apachecxf
2.4.4
apachecxf
2.4.5
apachecxf
2.4.6
apachecxf
2.4.7
apachecxf
2.5.0
apachecxf
2.5.1
apachecxf
2.5.2
apachecxf
2.5.3
apachecxf
2.6.0
𝑥
= Vulnerable software versions
References