5
CVSSv2

CVE-2013-0239

Published: 12/03/2013 Updated: 13/02/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Apache CXF prior to 2.5.9, 2.6.x prior to 2.6.6, and 2.7.x prior to 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote malicious users to bypass authentication via a security header of a SOAP request containing a UsernameToken element that lacks a password child element.

Vulnerable Product Search on Vulmon Subscribe to Product

apache cxf 2.5.2

apache cxf 2.4.6

apache cxf 2.5.3

apache cxf 2.4.0

apache cxf 2.4.3

apache cxf 2.5.7

apache cxf 2.4.4

apache cxf 2.4.2

apache cxf 2.5.0

apache cxf 2.5.1

apache cxf 2.5.5

apache cxf

apache cxf 2.4.1

apache cxf 2.5.6

apache cxf 2.4.7

apache cxf 2.4.5

apache cxf 2.5.4

apache cxf 2.6.0

apache cxf 2.6.2

apache cxf 2.6.5

apache cxf 2.6.3

apache cxf 2.6.4

apache cxf 2.6.1

apache cxf 2.7.0

apache cxf 2.7.1

apache cxf 2.7.2

Vendor Advisories

Synopsis Important: apache-cxf security update Type/Severity Security Advisory: Important Topic An updated apache-cxf package for JBoss Enterprise Application Platform601 which fixes two security issues is now available for Red HatEnterprise Linux 5 and 6The Red Hat Security Response Team has rated this ...
Synopsis Important: apache-cxf security update Type/Severity Security Advisory: Important Topic An update for the Apache CXF component of JBoss Portal Platform 600 whichfixes two security issues is now available from the Red Hat CustomerPortalThe Red Hat Security Response Team has rated this update as ha ...