CVE-2014-3623
Last modified
CVE-2014-3623 is a vulnerability of currently unknown severity. Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers to conduct spoofing attacks via unspecified vectors.. EPSS estimates a 9.22% chance of exploitation in the next 30 days.
Description
Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers to conduct spoofing attacks via unspecified vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Wss4j | < 1.6.17 |
| Apache | Wss4j | >= 2.0.0, < 2.0.2 |
| Apache | Cxf | >= 2.7.0, <= 2.7.13 |
| Apache | Cxf | >= 3.0.0, < 3.0.2 |
References
- http://rhn.redhat.com/errata/RHSA-2015-0236.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0675.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0850.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0851.htmlThird Party Advisory
- http://seclists.org/oss-sec/2014/q4/437Mailing List, Third Party Advisory
- http://secunia.com/advisories/61909Third Party Advisory
- http://www.securityfocus.com/bid/70736Third Party Advisory, VDB Entry
- https://issues.apache.org/jira/browse/WSS-511Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0236.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0675.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0850.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0851.htmlThird Party Advisory
- http://seclists.org/oss-sec/2014/q4/437Mailing List, Third Party Advisory
- http://secunia.com/advisories/61909Third Party Advisory
- http://www.securityfocus.com/bid/70736Third Party Advisory, VDB Entry
- https://issues.apache.org/jira/browse/WSS-511Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-3623?
How severe is CVE-2014-3623?
How do I fix CVE-2014-3623?
Are you affected by CVE-2014-3623?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
