5
CVSSv2

CVE-2014-3623

Published: 30/10/2014 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Apache WSS4J prior to 1.6.17 and 2.x prior to 2.0.2, as used in Apache CXF 2.7.x prior to 2.7.13 and 3.0.x prior to 3.0.2, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation method security semantics, which allows remote malicious users to conduct spoofing attacks via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache wss4j

apache cxf

Vendor Advisories

Synopsis Important: Red Hat JBoss Enterprise Application Platform 632 security update Type/Severity Security Advisory: Important Topic Updated Red Hat JBoss Enterprise Application Platform 632 packages thatfix three security issues are now available for Red Hat Enterprise Linux 5,6, and 7Red Hat Produc ...
It was found that Apache WSS4J (Web Services Security for Java), as used by Apache CXF with the TransportBinding, did not, by default, properly enforce all security requirements associated with SAML SubjectConfirmation methods A remote attacker could use this flaw to perform various types of spoofing attacks on web service endpoints secured by WSS ...