CVE-2013-5679

Owasp Enterprise Security API < 2.1.0 - Cryptographic Issue

Title source: rule

Description

The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ESAPI) for Java 2.x before 2.1.0 does not properly resist tampering with serialized ciphertext, which makes it easier for remote attackers to bypass intended cryptographic protection mechanisms via an attack against authenticity in the default configuration, involving a null MAC and a zero MAC length.

Exploits (2)

nomisec WORKING POC
by dawetmaster · poc
https://github.com/dawetmaster/CVE-2013-5679-esapi-java-legacy-vulnerable
nomisec WORKING POC
by andikahilmy · poc
https://github.com/andikahilmy/CVE-2013-5679-esapi-java-legacy-vulnerable

Scores

EPSS 0.0005
EPSS Percentile 16.5%

Details

CWE
CWE-310
Status published
Products (3)
org.owasp.esapi/esapi 2.0.0 - 2.1.0Maven
owasp/enterprise_security_api 2.0
owasp/enterprise_security_api 2.0.1
Published Sep 30, 2013
Tracked Since Feb 18, 2026