imPC@ndo IT

Tracker / CVE-2011-2487

CVE-2011-2487

Medium 5.9

The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.

Affected products and versions

apache cxf · 2.4.0 → 2.4.6
apache cxf · 2.5.0 → 2.5.2
apache wss4j · … → 1.6.5
redhat jboss_business_rules_management_system
redhat jboss_enterprise_application_platform
redhat jboss_enterprise_application_platform_text-only_advisories
redhat jboss_enterprise_soa_platform
redhat jboss_enterprise_web_platform
redhat jboss_middleware_text-only_advisories
redhat jboss_portal
redhat jboss_web_services

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References