CVE-2012-5575
mediumCVSS v3 Base Score
6.4
AV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS Score
9.5%
Exploitation probability in 30 days
Top 7% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Confidentiality
P
Integrity
P
Availability
None
Vulnerability Report
Generated by CyberWatcher
Description
Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack."
CWE
CWE-310Affected Products
apache cxfredhat jboss enterprise application platformredhat jboss enterprise portal platformredhat jboss enterprise soa platformredhat jboss enterprise web platformredhat jboss fuse esb enterprise