Deployments using Apache WSS4J versions before 4.0.2 in the 4.0.0 line, before 3.0.6 in the 3.0.0 line, or before 2.4.4 are affected. Exposure occurs when WSS4J processes SOAP messages with X.509 certificate-based signature key references.
No. The vulnerable DER decoding occurs while WSS4J resolves the signature key reference, before the SOAP message is authenticated. An unauthenticated attacker can send a crafted SOAP message containing an X.509 certificate with a malicious SubjectKeyIdentifier extension.
A crafted eleven-byte extension declaring a length of 0x7FFFFFFF can cause a 2 GB allocation. Repeated requests can exhaust server memory and cause a denial of service.
Upgrade to Apache WSS4J 4.0.2, 3.0.6, or 2.4.4, as applicable to the deployed release line.