{"api_version":"1","generated_at":"2026-05-13T01:06:46+00:00","cve":"CVE-2015-0226","urls":{"html":"https://cve.report/CVE-2015-0226","api":"https://cve.report/api/cve/CVE-2015-0226.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-0226","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-0226"},"summary":{"title":"CVE-2015-0226","description":"Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series of crafted messages. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-2487.","state":"PUBLISHED","assigner":"redhat","published_at":"2017-10-30 14:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-327","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03900en_us","name":"https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03900en_us","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Document Display | HPE Support Center","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-0848.html","name":"http://rhn.redhat.com/errata/RHSA-2015-0848.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-0847.html","name":"http://rhn.redhat.com/errata/RHSA-2015-0847.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","name":"https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Oracle Critical Patch Update - July 2019","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-1177.html","name":"http://rhn.redhat.com/errata/RHSA-2015-1177.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-1176.html","name":"http://rhn.redhat.com/errata/RHSA-2015-1176.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/72553","name":"http://www.securityfocus.com/bid/72553","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Apache WSS4J CVE-2015-0226 Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://access.redhat.com/errata/RHSA-2016:1376","name":"https://access.redhat.com/errata/RHSA-2016:1376","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal - Access to 24x7 support and knowledge","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://ws.apache.org/wss4j/advisories/CVE-2015-0226.txt.asc","name":"https://ws.apache.org/wss4j/advisories/CVE-2015-0226.txt.asc","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-0846.html","name":"http://rhn.redhat.com/errata/RHSA-2015-0846.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-0849.html","name":"http://rhn.redhat.com/errata/RHSA-2015-0849.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-0226","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-0226","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"226","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"wss4j","cpe6":"2.0","cpe7":"beta","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"226","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"wss4j","cpe6":"2.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"226","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"wss4j","cpe6":"2.0.0","cpe7":"rc1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"226","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"wss4j","cpe6":"2.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"226","vulnerable":"1","versionEndIncluding":"1.6.16","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"wss4j","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T04:03:10.543Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"RHSA-2016:1376","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"https://access.redhat.com/errata/RHSA-2016:1376"},{"name":"RHSA-2015:0849","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2015-0849.html"},{"name":"RHSA-2015:1176","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2015-1176.html"},{"name":"RHSA-2015:1177","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2015-1177.html"},{"name":"RHSA-2015:0848","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2015-0848.html"},{"name":"RHSA-2015:0846","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2015-0846.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03900en_us"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://ws.apache.org/wss4j/advisories/CVE-2015-0226.txt.asc"},{"name":"RHSA-2015:0847","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2015-0847.html"},{"name":"72553","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/72553"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-02-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series of crafted messages. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-2487."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2019-07-23T22:31:30.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"RHSA-2016:1376","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2016:1376"},{"name":"RHSA-2015:0849","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2015-0849.html"},{"name":"RHSA-2015:1176","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2015-1176.html"},{"name":"RHSA-2015:1177","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2015-1177.html"},{"name":"RHSA-2015:0848","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2015-0848.html"},{"name":"RHSA-2015:0846","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2015-0846.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03900en_us"},{"tags":["x_refsource_CONFIRM"],"url":"https://ws.apache.org/wss4j/advisories/CVE-2015-0226.txt.asc"},{"name":"RHSA-2015:0847","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2015-0847.html"},{"name":"72553","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/72553"},{"tags":["x_refsource_MISC"],"url":"https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2015-0226","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series of crafted messages. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-2487."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"RHSA-2016:1376","refsource":"REDHAT","url":"https://access.redhat.com/errata/RHSA-2016:1376"},{"name":"RHSA-2015:0849","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2015-0849.html"},{"name":"RHSA-2015:1176","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2015-1176.html"},{"name":"RHSA-2015:1177","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2015-1177.html"},{"name":"RHSA-2015:0848","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2015-0848.html"},{"name":"RHSA-2015:0846","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2015-0846.html"},{"name":"https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03900en_us","refsource":"CONFIRM","url":"https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03900en_us"},{"name":"https://ws.apache.org/wss4j/advisories/CVE-2015-0226.txt.asc","refsource":"CONFIRM","url":"https://ws.apache.org/wss4j/advisories/CVE-2015-0226.txt.asc"},{"name":"RHSA-2015:0847","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2015-0847.html"},{"name":"72553","refsource":"BID","url":"http://www.securityfocus.com/bid/72553"},{"name":"https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","refsource":"MISC","url":"https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html"}]}}}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2015-0226","datePublished":"2017-10-30T14:00:00.000Z","dateReserved":"2014-11-18T00:00:00.000Z","dateUpdated":"2024-08-06T04:03:10.543Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-10-30 14:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-327","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apache:wss4j:*:*:*:*:*:*:*:*","versionEndIncluding":"1.6.16","matchCriteriaId":"74202DCA-B961-4842-B4F5-BC9BE9F57CF4"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:wss4j:2.0:beta:*:*:*:*:*:*","matchCriteriaId":"4DE40CF6-930C-4B29-9E0F-8CB2DD29C569"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:wss4j:2.0.0:*:*:*:*:*:*:*","matchCriteriaId":"B6908C68-6E5B-4412-A6B1-E87EAA76249D"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:wss4j:2.0.0:rc1:*:*:*:*:*:*","matchCriteriaId":"1BCF037D-27B1-40C8-A501-64818D7B6E02"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:wss4j:2.0.1:*:*:*:*:*:*:*","matchCriteriaId":"ACFB231E-B649-4A7F-B9D0-DC0BACC0B682"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"226","Ordinal":"1","Title":"CVE-2015-0226","CVE":"CVE-2015-0226","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"226","Ordinal":"1","NoteData":"Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series of crafted messages. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-2487.","Type":"Description","Title":"CVE-2015-0226"},{"CveYear":"2015","CveId":"226","Ordinal":"2","NoteData":"2017-10-30","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"226","Ordinal":"3","NoteData":"2019-07-23","Type":"Other","Title":"Modified"}]}}}