First published: Tue Nov 27 2012(Updated: )
Tibor Jager, Kenneth G. Paterson and Juraj Somorovsky have described XML encryption backwards compatibility attacks against various frameworks, including Apache CXF. An attacker can use these flaws to force a server to utilize insecure, legacy cryptosystems when secure cryptosystems are enabled on endpoints. This could expose flaws in the underlying legacy cryptosystems, such as <a href="https://access.redhat.com/security/cve/CVE-2011-1096">CVE-2011-1096</a> and <a href="https://access.redhat.com/security/cve/CVE-2011-2487">CVE-2011-2487</a>. This flaw also affects the jbossws-native stack.
Affected Software | Affected Version | How to fix |
---|---|---|
Apache CXF | ||
Red Hat JBoss Web Services |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-880443 is classified as high due to potential exploitation that could force insecure cryptosystems.
To fix REDHAT-BUG-880443, update to the latest version of Apache CXF or Red Hat jbossws-native where the vulnerability has been patched.
REDHAT-BUG-880443 is associated with XML encryption backwards compatibility attacks that exploit insecure legacy cryptosystems.
The frameworks impacted by REDHAT-BUG-880443 include Apache CXF and Red Hat jbossws-native.
The vulnerability identified as REDHAT-BUG-880443 was discovered by Tibor Jager, Kenneth G. Paterson, and Juraj Somorovsky.