CVE-2013-5960

Owasp Enterprise Security API < 2.1.0.1 - Cryptographic Issue

Title source: rule

Description

The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ESAPI) for Java 2.x before 2.1.0.1 does not properly resist tampering with serialized ciphertext, which makes it easier for remote attackers to bypass intended cryptographic protection mechanisms via an attack against the intended cipher mode in a non-default configuration, a different vulnerability than CVE-2013-5679.

Exploits (2)

nomisec WORKING POC
by dawetmaster · poc
https://github.com/dawetmaster/CVE-2013-5960-esapi-java-legacy-vulnerable
nomisec WORKING POC
by andikahilmy · poc
https://github.com/andikahilmy/CVE-2013-5960-esapi-java-legacy-vulnerable

Scores

EPSS 0.0017
EPSS Percentile 38.6%

Details

CWE
CWE-310
Status published
Products (2)
org.owasp.esapi/esapi 2.0.0.0 - 2.1.0.1Maven
owasp/enterprise_security_api 2.0 - 2.1.0.1
Published Sep 30, 2013
Tracked Since Feb 18, 2026