5
CVSSv2

CVE-2015-0227

Published: 12/02/2015 Updated: 04/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Apache WSS4J prior to 1.6.17 and 2.x prior to 2.0.2 allows remote malicious users to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache wss4j 2.0.0

apache wss4j 2.0.1

apache wss4j

Vendor Advisories

Debian Bug report logs - #777741 wss4j: CVE-2015-0226 CVE-2015-0227 Package: wss4j; Maintainer for wss4j is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Thu, 12 Feb 2015 06:21:02 UTC Severity: grave Tags: security Fixed in version wss4 ...