Back

MEDIUM

jbossws: Prone to Bleichenbacher attack against to be distributed symmetric key

Published Mar 11, 2020

Description

The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.

Affected products

Remediation

Red Hat statement

This flaw affects Apache CXF (WSS4J) and jbossws-native as shipped with various JBoss products. It does not affect JBoss Enterprise Application Platform 6 and JBoss Application Server 7.1.1 and above. These products include WSS4J 1.6.5, which incorporates a fix for this flaw. On affected products, this flaw can be mitigated by using the RSA-OAEP key wrap algorithm, instead of the default RSA-v1.5 algorithm. To use RSA-OAEP, edit the jboss-ws-security configuration file and add the property keyWrapAlgorithm="rsa_oaep" to the encrypt element.

Metrics

References (39)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 11, 2020
Updated Aug 6, 2024
Reserved Jun 15, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Sep 4, 2012
GHSA-4QQF-HMV6-R6WH