REDHAT-BUG-880443: High severity apache cxf vulnerability
Tibor Jager, Kenneth G. Paterson and Juraj Somorovsky have described XML encryption backwards compatibility attacks against various frameworks, including Apache CXF. An attacker can use these flaws to force a server to utilize insecure, legacy cryptosystems when secure cryptosystems are enabled on endpoints. This could expose flaws in the underlying legacy cryptosystems, such as CVE-2011-1096 and CVE-2011-2487. This flaw also affects the jbossws-native stack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-880443?
The severity of REDHAT-BUG-880443 is classified as high due to potential exploitation that could force insecure cryptosystems.
How do I fix REDHAT-BUG-880443?
To fix REDHAT-BUG-880443, update to the latest version of Apache CXF or Red Hat jbossws-native where the vulnerability has been patched.
What type of attacks are associated with REDHAT-BUG-880443?
REDHAT-BUG-880443 is associated with XML encryption backwards compatibility attacks that exploit insecure legacy cryptosystems.
Which frameworks are impacted by REDHAT-BUG-880443?
The frameworks impacted by REDHAT-BUG-880443 include Apache CXF and Red Hat jbossws-native.
Who discovered the vulnerability identified as REDHAT-BUG-880443?
The vulnerability identified as REDHAT-BUG-880443 was discovered by Tibor Jager, Kenneth G. Paterson, and Juraj Somorovsky.