Back

MEDIUM

apache-cxf: UsernameTokenPolicyValidator and UsernameTokenInterceptor allow empty passwords to authenticate

Published Mar 12, 2013

Description

Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request containing a UsernameToken element that lacks a password child element.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (28)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 12, 2013
Updated Aug 6, 2024
Reserved Dec 6, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Feb 8, 2013
GHSA-P5C5-6564-VVR8