CVE-2015-0226
Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.50%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series of crafted messages. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-2487.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 5.50% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-327
- Affected
- apache/wss4j
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2015-0846.html
- http://rhn.redhat.com/errata/RHSA-2015-0847.html
- http://rhn.redhat.com/errata/RHSA-2015-0848.html
- http://rhn.redhat.com/errata/RHSA-2015-0849.html
- http://rhn.redhat.com/errata/RHSA-2015-1176.html
- http://rhn.redhat.com/errata/RHSA-2015-1177.html
- http://www.securityfocus.com/bid/72553Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2016:1376
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03900en_us
- https://ws.apache.org/wss4j/advisories/CVE-2015-0226.txt.ascIssue Tracking, Vendor Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
- http://rhn.redhat.com/errata/RHSA-2015-0846.html
- http://rhn.redhat.com/errata/RHSA-2015-0847.html
- http://rhn.redhat.com/errata/RHSA-2015-0848.html
- http://rhn.redhat.com/errata/RHSA-2015-0849.html
- http://rhn.redhat.com/errata/RHSA-2015-1176.html
- http://rhn.redhat.com/errata/RHSA-2015-1177.html
- http://www.securityfocus.com/bid/72553Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2016:1376
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03900en_us
- https://ws.apache.org/wss4j/advisories/CVE-2015-0226.txt.ascIssue Tracking, Vendor Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.