CVE-2013-0239

Apache Cxf < 2.5.8 - Authentication Bypass

Title source: rule

Description

Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request containing a UsernameToken element that lacks a password child element.

References (15)

Scores

EPSS 0.0265
EPSS Percentile 85.6%

Classification

CWE
CWE-287
Status draft

Affected Products (27)

apache/cxf < 2.5.8
apache/cxf
apache/cxf
apache/cxf
apache/cxf
apache/cxf
apache/cxf
apache/cxf
apache/cxf
apache/cxf
apache/cxf
apache/cxf
apache/cxf
apache/cxf
apache/cxf
... and 12 more

Timeline

Published Mar 12, 2013
Tracked Since Feb 18, 2026