CVE Database
/

CVE-2012-2379

Back to search

CVE-2012-2379

Published: Jan 3, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and attack vectors.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2012:1559
vendor-advisory
x_refsource_REDHAT
RHSA-2013:0192
vendor-advisory
x_refsource_REDHAT
RHSA-2013:0198
vendor-advisory
x_refsource_REDHAT
RHSA-2012:1594
vendor-advisory
x_refsource_REDHAT
RHSA-2013:0195
vendor-advisory
x_refsource_REDHAT
RHSA-2013:0196
vendor-advisory
x_refsource_REDHAT
51607
third-party-advisory
x_refsource_SECUNIA
RHSA-2013:0193
vendor-advisory
x_refsource_REDHAT
51984
third-party-advisory
x_refsource_SECUNIA
RHSA-2012:1592
vendor-advisory
x_refsource_REDHAT
RHSA-2013:0191
vendor-advisory
x_refsource_REDHAT
RHSA-2012:1593
vendor-advisory
x_refsource_REDHAT
RHSA-2012:1573
vendor-advisory
x_refsource_REDHAT
RHSA-2012:1591
vendor-advisory
x_refsource_REDHAT
RHSA-2013:0197
vendor-advisory
x_refsource_REDHAT
RHSA-2013:0194
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now