Apache / Wss4j
8 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-92899 | Apache WSS4J: UsernameToken replay protection bypassed by re-encoding the Nonce | MEDIUM | 4.8 | Sep 30, 2026 |
| CVE-2026-88920 | Apache WSS4J: SAML Sender-Vouches Authentication Bypass | CRITICAL | 9.8 | Sep 30, 2026 |
| CVE-2026-85532 | Apache WSS4J: Insufficient Validation of Derived-Key Parameters | HIGH | 7.5 | Sep 30, 2026 |
| CVE-2020-13936 | Velocity Sandbox Bypass | HIGH | 8.8 | Mar 10, 2021 |
| CVE-2011-2487 | jbossws: Prone to Bleichenbacher attack against to be distributed symmetric key | MEDIUM | 5.9 | Mar 11, 2020 |
| CVE-2015-0226 | wss4j: Apache WSS4J is vulnerable to Bleichenbacher's attack (incomplete fix for CVE-2011-2487) | HIGH | 7.5 | Oct 30, 2017 |
| CVE-2015-0227 | wss4j: Apache WSS4J doesn't correctly enforce the requireSignedEncryptedDataElements property | MEDIUM | 5.0 | Feb 12, 2015 |
| CVE-2014-3623 | CXF: Improper security semantics enforcement of SAML SubjectConfirmation methods | MEDIUM | 5.0 | Oct 30, 2014 |
Showing 1 to 8 of 8 CVEs