CVE
- Id
- 58876
- CVE No.
- CVE-2012-5633
- Status
- Candidate
- Description
- The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.
- Phase
- Assigned (20121024)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
| Id | CVE Id | CVE No. | Reference | Actions |
|---|---|---|---|---|
| 602136 | 58876 | CVE-2012-5633 | FULLDISC:20130208 New security advisories for Apache CXF | View |
| 602137 | 58876 | CVE-2012-5633 | URL:http://seclists.org/fulldisclosure/2013/Feb/39 | View |
| 602138 | 58876 | CVE-2012-5633 | MISC:http://packetstormsecurity.com/files/120213/Apache-CXF-WS-Security-URIMappingInterceptor-Bypass.html | View |
| 602139 | 58876 | CVE-2012-5633 | MISC:http://stackoverflow.com/questions/7933293/why-does-apache-cxf-ws-security-implementation-ignore-get-requests | View |
| 602140 | 58876 | CVE-2012-5633 | MISC:https://issues.jboss.org/browse/JBWS-3575 | View |
| 602141 | 58876 | CVE-2012-5633 | CONFIRM:http://cxf.apache.org/cve-2012-5633.html | View |
| 602142 | 58876 | CVE-2012-5633 | CONFIRM:http://svn.apache.org/viewvc?view=revision&revision=1409324 | View |
| 602143 | 58876 | CVE-2012-5633 | CONFIRM:http://svn.apache.org/viewvc?view=revision&revision=1420698 | View |
| 602144 | 58876 | CVE-2012-5633 | CONFIRM:https://issues.apache.org/jira/browse/CXF-4629 | View |
| 602145 | 58876 | CVE-2012-5633 | REDHAT:RHSA-2013:0256 | View |
| 602146 | 58876 | CVE-2012-5633 | URL:http://rhn.redhat.com/errata/RHSA-2013-0256.html | View |
| 602147 | 58876 | CVE-2012-5633 | REDHAT:RHSA-2013:0257 | View |
| 602148 | 58876 | CVE-2012-5633 | URL:http://rhn.redhat.com/errata/RHSA-2013-0257.html | View |
| 602149 | 58876 | CVE-2012-5633 | REDHAT:RHSA-2013:0258 | View |
| 602150 | 58876 | CVE-2012-5633 | URL:http://rhn.redhat.com/errata/RHSA-2013-0258.html | View |
| 602151 | 58876 | CVE-2012-5633 | REDHAT:RHSA-2013:0259 | View |
| 602152 | 58876 | CVE-2012-5633 | URL:http://rhn.redhat.com/errata/RHSA-2013-0259.html | View |
| 602153 | 58876 | CVE-2012-5633 | REDHAT:RHSA-2013:0726 | View |
| 602154 | 58876 | CVE-2012-5633 | URL:http://rhn.redhat.com/errata/RHSA-2013-0726.html | View |
| 602155 | 58876 | CVE-2012-5633 | REDHAT:RHSA-2013:0743 | View |
| 602156 | 58876 | CVE-2012-5633 | URL:http://rhn.redhat.com/errata/RHSA-2013-0743.html | View |
| 602157 | 58876 | CVE-2012-5633 | REDHAT:RHSA-2013:0749 | View |
| 602158 | 58876 | CVE-2012-5633 | URL:http://rhn.redhat.com/errata/RHSA-2013-0749.html | View |
| 602159 | 58876 | CVE-2012-5633 | BID:57874 | View |
| 602160 | 58876 | CVE-2012-5633 | URL:http://www.securityfocus.com/bid/57874 | View |
| 602161 | 58876 | CVE-2012-5633 | OSVDB:90079 | View |
| 602162 | 58876 | CVE-2012-5633 | URL:http://osvdb.org/90079 | View |
| 602163 | 58876 | CVE-2012-5633 | SECUNIA:51988 | View |
| 602164 | 58876 | CVE-2012-5633 | URL:http://secunia.com/advisories/51988 | View |
| 602165 | 58876 | CVE-2012-5633 | SECUNIA:52183 | View |
| 602166 | 58876 | CVE-2012-5633 | URL:http://secunia.com/advisories/52183 | View |
| 602167 | 58876 | CVE-2012-5633 | XF:apachecxf-wssecurity-security-bypass(81980) | View |
Related JVN
| Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 30063 | JVNDB-2012-005770 | SANLock の log.h におけるファイルコンテンツを上書きされる脆弱性 | SANLock の log.h 内の setup_logging 関数は、/var/log/sanlock.log に対して、誰でも書き込みできる権限 (world-writable permissions) を使用するため、ファイルコンテンツを上書きされる、またはディスククオータ制限を回避される脆弱性が存在します。 | CVE-2012-5638 | 58876 | 3.6 | http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-005770.html | View |