CVE-2011-2487

MEDIUM

Apache CXF 2.4.0-2.4.5 and WSS4J < 1.6.5 - Bleichenbacher Attack via PKCS#1 v1.5 Key Transport

Title source: llm
STIX 2.1

Description

The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.

References (18)

Core 18
Core References
Issue Tracking, Patch, Vendor Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=713539
Technical Description, Third Party Advisory x_refsource_misc
https://www.nds.ruhr-uni-bochum.de/research/publications/breaking-xml-encryption-pkcs15/
Vendor Advisory x_refsource_misc
http://cxf.apache.org/note-on-cve-2011-2487.html
Patch, Vendor Advisory x_refsource_misc
http://rhn.redhat.com/errata/RHSA-2013-0191.html
Patch, Vendor Advisory x_refsource_misc
http://rhn.redhat.com/errata/RHSA-2013-0192.html
Broken Link, Patch, Vendor Advisory x_refsource_misc
http://rhn.redhat.com/errata/RHSA-2013-0193.html
Patch, Vendor Advisory x_refsource_misc
http://rhn.redhat.com/errata/RHSA-2013-0194.html
Patch, Vendor Advisory x_refsource_misc
http://rhn.redhat.com/errata/RHSA-2013-0195.html
Patch, Vendor Advisory x_refsource_misc
http://rhn.redhat.com/errata/RHSA-2013-0196.html
Patch, Vendor Advisory x_refsource_misc
http://rhn.redhat.com/errata/RHSA-2013-0198.html
Patch, Vendor Advisory x_refsource_misc
http://rhn.redhat.com/errata/RHSA-2013-0221.html
Third Party Advisory, VDB Entry x_refsource_misc
http://www.securityfocus.com/bid/57549
VDB Entry, Vendor Advisory x_refsource_misc
https://exchange.xforce.ibmcloud.com/vulnerabilities/81737

Scores

CVSS v3 5.9
EPSS 0.0176
EPSS Percentile 75.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-327
Status published
Products (13)
apache/cxf 2.4.0 - 2.4.6
apache/wss4j < 1.6.5
org.apache.ws.security/wss4j 0 - 1.6.5Maven
redhat/jboss_business_rules_management_system 5.3
redhat/jboss_enterprise_application_platform 5.0.0
redhat/jboss_enterprise_application_platform_text-only_advisories
redhat/jboss_enterprise_soa_platform 4.2.0
redhat/jboss_enterprise_soa_platform 4.3.0
redhat/jboss_enterprise_web_platform 5.0.0
redhat/jboss_middleware_text-only_advisories
... and 3 more
Published Mar 11, 2020
Tracked Since Feb 18, 2026