CVE-2011-2487

Aliases:GHSA-4qqf-hmv6-r6wh
Modified
Published: 11 Mar 2020, 15:45
Last modified:06 Aug 2024, 23:00

Vulnerability Summary

Overall Risk (default)
low
24/100
CVSS Score
5.9 MEDIUM
v3.1 (nvd)
EPSS Score
0.49% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

11 Mar 2020, 15:45
Published
Vulnerability first disclosed
06 Aug 2024, 23:00
Last Modified
Vulnerability information updated

Description

The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.

CVSS Metrics

  • v3.1MEDIUMScore: 5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 0.49% Percentile: 66%

Techniques & Countermeasures

  • CWE-327Use of a Broken or Risky Cryptographic Algorithm

    The product uses a broken or risky cryptographic algorithm or protocol.

Affected Systems

  • apachecxf

    ≥ 2.4.0, ≤ 2.4.6 | ≥ 2.5.0, ≤ 2.5.2

  • apachewss4j

    < 1.6.5

  • org.apache.ws.securitywss4j

    < 1.6.5

  • wss4jwss4j

    < 1.6.5

  • red hatjbossws

    unknown

  • redhatjboss_business_rules_management_system

    5.3

  • redhatjboss_enterprise_application_platform

    5.0.0

  • redhatjboss_enterprise_application_platform_text-only_advisories

    na

  • redhatjboss_enterprise_soa_platform

    4.2.0 | 4.3.0

  • redhatjboss_enterprise_web_platform

    5.0.0

  • redhatjboss_middleware_text-only_advisories

    na

  • redhatjboss_portal

    4.0.0

  • redhatjboss_web_services

    na

References (38)