Apache WSS4J Information Leakage Vulnerability (CVE-2015-0226)
Apache WSS4J Information Leakage Vulnerability (CVE-2015-0226)
Release date:
Updated on:
Affected Systems:
Apache Group WSS4J <2.0.2
Apache Group WSS4J <1.6.17
Description:
Bugtraq id: 72553
CVE (CAN) ID: CVE-2015-0226
WSS4J implements WS-Security, which is the Security module of AXIS, but can also be used in other Web Services frameworks (such as XFIRE and CXF ).
Apache WSS4J versions earlier than 1.6.17 and 2.0.2 have the information leakage vulnerability. By constructing messages, attackers can determine the locations where decryption fails and obtain sensitive information.
<* Source: vendor
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://ws.apache.org/wss4j/advisories/CVE-2015-0226.txt.asc
Http://svn.apache.org/viewvc? View = revision & revision = 1621329
Http://cxf.apache.org/note-on-cve-2011-2487.html
This article permanently updates the link address: