Back

HIGH

wss4j: Apache WSS4J is vulnerable to Bleichenbacher's attack (incomplete fix for CVE-2011-2487)

Published Oct 30, 2017

Description

Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series of crafted messages. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-2487.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (19)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 30, 2017
Updated Aug 6, 2024
Reserved Nov 18, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Feb 10, 2015
GHSA-VJWC-5HFH-2VV5