Skip to main content

Vendor/product archive

apache / wss4j CVEs

Beta · best-effort

5 CVEs tagged to apache / wss4j0 Critical, 2 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2015-0226

Published Oct 30, 2017

Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier fo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-0227

Published Feb 12, 2015

Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks."

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3623

Published Oct 30, 2014

Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1