CVE-2012-5575
apache-cxf: XML encryption backwards compatibility attacks
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack."
Apache CXF en versiones 2.5.x anteriores a la 2.5.10, 2.6.x anteriores a CXF 2.6.7 y 2.7.x anteriores a CXF 2.7.4 no verifica que un algoritmo criptográfico específico esté permitido por la definición de WS-SecurityPolicy AlgorithmSuite antes del descifrado, lo que permite a los atacantes remotos forzar a CXF a usar algoritmos criptográficos más débiles que los previstos y facilita el descifrado de las comunicaciones. Esto también se conoce como "XML Encryption backwards compatibility attack".
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-10-24 CVE Reserved
- 2013-05-20 CVE Published
- 2018-11-19 First Exploit
- 2024-05-06 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-310: Cryptographic Issues
- CWE-327: Use of a Broken or Risky Cryptographic Algorithm
CAPEC
References (23)
URL | Date | SRC |
---|---|---|
https://github.com/tafamace/CVE-2012-5575 | 2018-11-19 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2013-0833.html | 2023-02-13 | |
http://rhn.redhat.com/errata/RHSA-2013-0834.html | 2023-02-13 | |
http://rhn.redhat.com/errata/RHSA-2013-0839.html | 2023-02-13 | |
http://rhn.redhat.com/errata/RHSA-2013-0873.html | 2023-02-13 | |
http://rhn.redhat.com/errata/RHSA-2013-0874.html | 2023-02-13 | |
http://rhn.redhat.com/errata/RHSA-2013-0875.html | 2023-02-13 | |
http://rhn.redhat.com/errata/RHSA-2013-0876.html | 2023-02-13 | |
http://rhn.redhat.com/errata/RHSA-2013-0943.html | 2023-02-13 | |
http://rhn.redhat.com/errata/RHSA-2013-1028.html | 2023-02-13 | |
http://rhn.redhat.com/errata/RHSA-2013-1143.html | 2023-02-13 | |
http://rhn.redhat.com/errata/RHSA-2013-1437.html | 2023-02-13 | |
https://bugzilla.redhat.com/show_bug.cgi?id=880443 | 2013-10-16 | |
https://access.redhat.com/security/cve/CVE-2012-5575 | 2013-10-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Cxf Search vendor "Apache" for product "Cxf" | 2.5.0 Search vendor "Apache" for product "Cxf" and version "2.5.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Cxf Search vendor "Apache" for product "Cxf" | 2.5.1 Search vendor "Apache" for product "Cxf" and version "2.5.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Cxf Search vendor "Apache" for product "Cxf" | 2.5.2 Search vendor "Apache" for product "Cxf" and version "2.5.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Cxf Search vendor "Apache" for product "Cxf" | 2.5.3 Search vendor "Apache" for product "Cxf" and version "2.5.3" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Cxf Search vendor "Apache" for product "Cxf" | 2.5.4 Search vendor "Apache" for product "Cxf" and version "2.5.4" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Cxf Search vendor "Apache" for product "Cxf" | 2.5.5 Search vendor "Apache" for product "Cxf" and version "2.5.5" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Cxf Search vendor "Apache" for product "Cxf" | 2.5.6 Search vendor "Apache" for product "Cxf" and version "2.5.6" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Cxf Search vendor "Apache" for product "Cxf" | 2.5.7 Search vendor "Apache" for product "Cxf" and version "2.5.7" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Cxf Search vendor "Apache" for product "Cxf" | 2.5.8 Search vendor "Apache" for product "Cxf" and version "2.5.8" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Cxf Search vendor "Apache" for product "Cxf" | 2.5.9 Search vendor "Apache" for product "Cxf" and version "2.5.9" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Cxf Search vendor "Apache" for product "Cxf" | 2.6.0 Search vendor "Apache" for product "Cxf" and version "2.6.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Cxf Search vendor "Apache" for product "Cxf" | 2.6.1 Search vendor "Apache" for product "Cxf" and version "2.6.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Cxf Search vendor "Apache" for product "Cxf" | 2.6.2 Search vendor "Apache" for product "Cxf" and version "2.6.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Cxf Search vendor "Apache" for product "Cxf" | 2.6.3 Search vendor "Apache" for product "Cxf" and version "2.6.3" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Cxf Search vendor "Apache" for product "Cxf" | 2.6.4 Search vendor "Apache" for product "Cxf" and version "2.6.4" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Cxf Search vendor "Apache" for product "Cxf" | 2.6.5 Search vendor "Apache" for product "Cxf" and version "2.6.5" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Cxf Search vendor "Apache" for product "Cxf" | 2.6.6 Search vendor "Apache" for product "Cxf" and version "2.6.6" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Cxf Search vendor "Apache" for product "Cxf" | 2.7.0 Search vendor "Apache" for product "Cxf" and version "2.7.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Cxf Search vendor "Apache" for product "Cxf" | 2.7.1 Search vendor "Apache" for product "Cxf" and version "2.7.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Cxf Search vendor "Apache" for product "Cxf" | 2.7.2 Search vendor "Apache" for product "Cxf" and version "2.7.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Cxf Search vendor "Apache" for product "Cxf" | 2.7.3 Search vendor "Apache" for product "Cxf" and version "2.7.3" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Enterprise Application Platform Search vendor "Redhat" for product "Jboss Enterprise Application Platform" | 5.0.0 Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version "5.0.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Enterprise Portal Platform Search vendor "Redhat" for product "Jboss Enterprise Portal Platform" | 4.3.0 Search vendor "Redhat" for product "Jboss Enterprise Portal Platform" and version "4.3.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Enterprise Soa Platform Search vendor "Redhat" for product "Jboss Enterprise Soa Platform" | 4.3.0 Search vendor "Redhat" for product "Jboss Enterprise Soa Platform" and version "4.3.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Enterprise Web Platform Search vendor "Redhat" for product "Jboss Enterprise Web Platform" | 5.2.0 Search vendor "Redhat" for product "Jboss Enterprise Web Platform" and version "5.2.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Fuse Esb Enterprise Search vendor "Redhat" for product "Jboss Fuse Esb Enterprise" | 7.1.0 Search vendor "Redhat" for product "Jboss Fuse Esb Enterprise" and version "7.1.0" | - |
Affected
|