CVE-2015-0227

Apache WSS4J < 1.6.17 and 2.x < 2.0.2 - Security Feature Bypass via Wrapping Attacks

Title source: llm
STIX 2.1

Description

Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks."

References (12)

Core 12
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/100837
Patch, Vendor Advisory x_refsource_confirm
http://ws.apache.org/wss4j/advisories/CVE-2015-0227.txt.asc
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/72557
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0773.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0849.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-1176.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-1177.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0848.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0846.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0847.html

Scores

EPSS 0.1387
EPSS Percentile 94.4%

Details

CWE
CWE-264
Status published
Products (5)
apache/wss4j 2.0.0 (2 CPE variants)
apache/wss4j 2.0.1
apache/wss4j < 1.6.16
org.apache.ws.security/wss4j 0 - 1.6.17Maven
wss4j/wss4j 0 - 1.6.17Maven
Published Feb 12, 2015
Tracked Since Feb 18, 2026