SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-0226

Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a…

HIGH 7.5EPSS 5.50%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (5.50%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series of crafted messages. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-2487.

CVSS 3.0
7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
5.50% probability · 92th percentile
CISA KEV
Not listed
Weakness
CWE-327
Affected
apache/wss4j
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.