CVE-2013-5679
Summary
| CVE | CVE-2013-5679 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-09-30 17:09:26 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ESAPI) for Java 2.x before 2.1.0 does not properly resist tampering with serialized ciphertext, which makes it easier for remote attackers to bypass intended cryptographic protection mechanisms via an attack against authenticity in the default configuration, involving a null MAC and a zero MAC length. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
HighAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:L/AC:H/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Owasp | Enterprise Security Api | 2.0 | All | All | All |
| Application | Owasp | Enterprise Security Api | 2.0.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Issue 306 - owasp-esapi-java - Crypto MAC by-pass makes default ESAPI symmetric encrytion using CBC mode vulnerable to padding oracle attacks - OWASP Enterprise Security API (Java Edition) - Google Project Hosting | af854a3a-2127-422b-91ae-364da2661108 | code.google.com | Exploit |
| OWASP ESAPI CBC Mode HMAC Authentication Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| [Esapi-dev] ESAPI Java and Authenticated encryption implementation | af854a3a-2127-422b-91ae-364da2661108 | lists.owasp.org | |
| Error 404 (Not Found)!!1 | af854a3a-2127-422b-91ae-364da2661108 | owasp-esapi-java.googlecode.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.