Apache WSS4J Security Restriction Bypass Vulnerability (CVE-2015-0227)
Release date:
Updated on:
Affected Systems:
Apache Group WSS4J <2.0.2
Apache Group WSS4J <1.6.17
Apache Group WSS4J
Description:
Bugtraq id: 72557
CVE (CAN) ID: CVE-2015-0227
WSS4J implements WS-Security, which is the Security module of AXIS, but can also be used in other Web Services frameworks (such as XFIRE and CXF ).
Apache WSS4J versions earlier than 1.6.17 and 2.0.2. After the "requireSignedEncryptedDataElements" Boolean Configuration Attribute is set, the signature subtree of the document contains the EncryptedData element. The default value of this attribute is "false ", however, this setting can be tampered with through multiple types of packaging attacks.
<* Source: vendor
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://ws.apache.org/wss4j/
Http://ws.apache.org/wss4j/security_advisories.html
Http://ws.apache.org/wss4j/advisories/CVE-2015-0227.txt.asc
This article permanently updates the link address: