CVE
- Id
- 58876
- CVE No.
- CVE-2012-5633
- Status
- Candidate
- Description
- The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.
- Phase
- Assigned (20121024)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
602136 | 58876 | CVE-2012-5633 | FULLDISC:20130208 New security advisories for Apache CXF | View |
602137 | 58876 | CVE-2012-5633 | URL:http://seclists.org/fulldisclosure/2013/Feb/39 | View |
602138 | 58876 | CVE-2012-5633 | MISC:http://packetstormsecurity.com/files/120213/Apache-CXF-WS-Security-URIMappingInterceptor-Bypass.html | View |
602139 | 58876 | CVE-2012-5633 | MISC:http://stackoverflow.com/questions/7933293/why-does-apache-cxf-ws-security-implementation-ignore-get-requests | View |
602140 | 58876 | CVE-2012-5633 | MISC:https://issues.jboss.org/browse/JBWS-3575 | View |
602141 | 58876 | CVE-2012-5633 | CONFIRM:http://cxf.apache.org/cve-2012-5633.html | View |
602142 | 58876 | CVE-2012-5633 | CONFIRM:http://svn.apache.org/viewvc?view=revision&revision=1409324 | View |
602143 | 58876 | CVE-2012-5633 | CONFIRM:http://svn.apache.org/viewvc?view=revision&revision=1420698 | View |
602144 | 58876 | CVE-2012-5633 | CONFIRM:https://issues.apache.org/jira/browse/CXF-4629 | View |
602145 | 58876 | CVE-2012-5633 | REDHAT:RHSA-2013:0256 | View |
602146 | 58876 | CVE-2012-5633 | URL:http://rhn.redhat.com/errata/RHSA-2013-0256.html | View |
602147 | 58876 | CVE-2012-5633 | REDHAT:RHSA-2013:0257 | View |
602148 | 58876 | CVE-2012-5633 | URL:http://rhn.redhat.com/errata/RHSA-2013-0257.html | View |
602149 | 58876 | CVE-2012-5633 | REDHAT:RHSA-2013:0258 | View |
602150 | 58876 | CVE-2012-5633 | URL:http://rhn.redhat.com/errata/RHSA-2013-0258.html | View |
602151 | 58876 | CVE-2012-5633 | REDHAT:RHSA-2013:0259 | View |
602152 | 58876 | CVE-2012-5633 | URL:http://rhn.redhat.com/errata/RHSA-2013-0259.html | View |
602153 | 58876 | CVE-2012-5633 | REDHAT:RHSA-2013:0726 | View |
602154 | 58876 | CVE-2012-5633 | URL:http://rhn.redhat.com/errata/RHSA-2013-0726.html | View |
602155 | 58876 | CVE-2012-5633 | REDHAT:RHSA-2013:0743 | View |
602156 | 58876 | CVE-2012-5633 | URL:http://rhn.redhat.com/errata/RHSA-2013-0743.html | View |
602157 | 58876 | CVE-2012-5633 | REDHAT:RHSA-2013:0749 | View |
602158 | 58876 | CVE-2012-5633 | URL:http://rhn.redhat.com/errata/RHSA-2013-0749.html | View |
602159 | 58876 | CVE-2012-5633 | BID:57874 | View |
602160 | 58876 | CVE-2012-5633 | URL:http://www.securityfocus.com/bid/57874 | View |
602161 | 58876 | CVE-2012-5633 | OSVDB:90079 | View |
602162 | 58876 | CVE-2012-5633 | URL:http://osvdb.org/90079 | View |
602163 | 58876 | CVE-2012-5633 | SECUNIA:51988 | View |
602164 | 58876 | CVE-2012-5633 | URL:http://secunia.com/advisories/51988 | View |
602165 | 58876 | CVE-2012-5633 | SECUNIA:52183 | View |
602166 | 58876 | CVE-2012-5633 | URL:http://secunia.com/advisories/52183 | View |
602167 | 58876 | CVE-2012-5633 | XF:apachecxf-wssecurity-security-bypass(81980) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
30063 | JVNDB-2012-005770 | SANLock の log.h におけるファイルコンテンツを上書きされる脆弱性 | SANLock の log.h 内の setup_logging 関数は、/var/log/sanlock.log に対して、誰でも書き込みできる権限 (world-writable permissions) を使用するため、ファイルコンテンツを上書きされる、またはディスククオータ制限を回避される脆弱性が存在します。 | CVE-2012-5638 | 58876 | 3.6 | http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-005770.html | View |