First published: Tue Jun 22 2021(Updated: )
It was found that all OWASP ESAPI for Java up to version 2.0 RC2 are vulnerable to padding oracle attacks.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OWASP Enterprise Security API | <2.0 | |
OWASP Enterprise Security API | =2.0 | |
OWASP Enterprise Security API | =2.0-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3300 is a vulnerability found in all OWASP ESAPI for Java up to version 2.0 RC2 that makes them vulnerable to padding oracle attacks.
CVE-2010-3300 has a severity rating of medium, with a severity value of 5.9.
CVE-2010-3300 affects all OWASP ESAPI for Java up to version 2.0 RC2, making them vulnerable to padding oracle attacks.
To fix the CVE-2010-3300 vulnerability, it is recommended to update OWASP ESAPI for Java to a version beyond 2.0 RC2.
More information about CVE-2010-3300 can be found at the following references: [link1], [link2].