// For flags

CVE-2012-5575

apache-cxf: XML encryption backwards compatibility attacks

Severity Score

6.4
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack."

Apache CXF en versiones 2.5.x anteriores a la 2.5.10, 2.6.x anteriores a CXF 2.6.7 y 2.7.x anteriores a CXF 2.7.4 no verifica que un algoritmo criptográfico específico esté permitido por la definición de WS-SecurityPolicy AlgorithmSuite antes del descifrado, lo que permite a los atacantes remotos forzar a CXF a usar algoritmos criptográficos más débiles que los previstos y facilita el descifrado de las comunicaciones. Esto también se conoce como "XML Encryption backwards compatibility attack".

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-10-24 CVE Reserved
  • 2013-05-20 CVE Published
  • 2018-11-19 First Exploit
  • 2024-05-06 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-310: Cryptographic Issues
  • CWE-327: Use of a Broken or Risky Cryptographic Algorithm
CAPEC
References (23)
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Apache
Search vendor "Apache"
Cxf
Search vendor "Apache" for product "Cxf"
2.5.0
Search vendor "Apache" for product "Cxf" and version "2.5.0"
-
Affected
Apache
Search vendor "Apache"
Cxf
Search vendor "Apache" for product "Cxf"
2.5.1
Search vendor "Apache" for product "Cxf" and version "2.5.1"
-
Affected
Apache
Search vendor "Apache"
Cxf
Search vendor "Apache" for product "Cxf"
2.5.2
Search vendor "Apache" for product "Cxf" and version "2.5.2"
-
Affected
Apache
Search vendor "Apache"
Cxf
Search vendor "Apache" for product "Cxf"
2.5.3
Search vendor "Apache" for product "Cxf" and version "2.5.3"
-
Affected
Apache
Search vendor "Apache"
Cxf
Search vendor "Apache" for product "Cxf"
2.5.4
Search vendor "Apache" for product "Cxf" and version "2.5.4"
-
Affected
Apache
Search vendor "Apache"
Cxf
Search vendor "Apache" for product "Cxf"
2.5.5
Search vendor "Apache" for product "Cxf" and version "2.5.5"
-
Affected
Apache
Search vendor "Apache"
Cxf
Search vendor "Apache" for product "Cxf"
2.5.6
Search vendor "Apache" for product "Cxf" and version "2.5.6"
-
Affected
Apache
Search vendor "Apache"
Cxf
Search vendor "Apache" for product "Cxf"
2.5.7
Search vendor "Apache" for product "Cxf" and version "2.5.7"
-
Affected
Apache
Search vendor "Apache"
Cxf
Search vendor "Apache" for product "Cxf"
2.5.8
Search vendor "Apache" for product "Cxf" and version "2.5.8"
-
Affected
Apache
Search vendor "Apache"
Cxf
Search vendor "Apache" for product "Cxf"
2.5.9
Search vendor "Apache" for product "Cxf" and version "2.5.9"
-
Affected
Apache
Search vendor "Apache"
Cxf
Search vendor "Apache" for product "Cxf"
2.6.0
Search vendor "Apache" for product "Cxf" and version "2.6.0"
-
Affected
Apache
Search vendor "Apache"
Cxf
Search vendor "Apache" for product "Cxf"
2.6.1
Search vendor "Apache" for product "Cxf" and version "2.6.1"
-
Affected
Apache
Search vendor "Apache"
Cxf
Search vendor "Apache" for product "Cxf"
2.6.2
Search vendor "Apache" for product "Cxf" and version "2.6.2"
-
Affected
Apache
Search vendor "Apache"
Cxf
Search vendor "Apache" for product "Cxf"
2.6.3
Search vendor "Apache" for product "Cxf" and version "2.6.3"
-
Affected
Apache
Search vendor "Apache"
Cxf
Search vendor "Apache" for product "Cxf"
2.6.4
Search vendor "Apache" for product "Cxf" and version "2.6.4"
-
Affected
Apache
Search vendor "Apache"
Cxf
Search vendor "Apache" for product "Cxf"
2.6.5
Search vendor "Apache" for product "Cxf" and version "2.6.5"
-
Affected
Apache
Search vendor "Apache"
Cxf
Search vendor "Apache" for product "Cxf"
2.6.6
Search vendor "Apache" for product "Cxf" and version "2.6.6"
-
Affected
Apache
Search vendor "Apache"
Cxf
Search vendor "Apache" for product "Cxf"
2.7.0
Search vendor "Apache" for product "Cxf" and version "2.7.0"
-
Affected
Apache
Search vendor "Apache"
Cxf
Search vendor "Apache" for product "Cxf"
2.7.1
Search vendor "Apache" for product "Cxf" and version "2.7.1"
-
Affected
Apache
Search vendor "Apache"
Cxf
Search vendor "Apache" for product "Cxf"
2.7.2
Search vendor "Apache" for product "Cxf" and version "2.7.2"
-
Affected
Apache
Search vendor "Apache"
Cxf
Search vendor "Apache" for product "Cxf"
2.7.3
Search vendor "Apache" for product "Cxf" and version "2.7.3"
-
Affected
Redhat
Search vendor "Redhat"
Jboss Enterprise Application Platform
Search vendor "Redhat" for product "Jboss Enterprise Application Platform"
5.0.0
Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version "5.0.0"
-
Affected
Redhat
Search vendor "Redhat"
Jboss Enterprise Portal Platform
Search vendor "Redhat" for product "Jboss Enterprise Portal Platform"
4.3.0
Search vendor "Redhat" for product "Jboss Enterprise Portal Platform" and version "4.3.0"
-
Affected
Redhat
Search vendor "Redhat"
Jboss Enterprise Soa Platform
Search vendor "Redhat" for product "Jboss Enterprise Soa Platform"
4.3.0
Search vendor "Redhat" for product "Jboss Enterprise Soa Platform" and version "4.3.0"
-
Affected
Redhat
Search vendor "Redhat"
Jboss Enterprise Web Platform
Search vendor "Redhat" for product "Jboss Enterprise Web Platform"
5.2.0
Search vendor "Redhat" for product "Jboss Enterprise Web Platform" and version "5.2.0"
-
Affected
Redhat
Search vendor "Redhat"
Jboss Fuse Esb Enterprise
Search vendor "Redhat" for product "Jboss Fuse Esb Enterprise"
7.1.0
Search vendor "Redhat" for product "Jboss Fuse Esb Enterprise" and version "7.1.0"
-
Affected