Apache Axis2 XML Signature Wrapping Security Vulnerability
BID:55508
Info
Apache Axis2 XML Signature Wrapping Security Vulnerability
| Bugtraq ID: | 55508 |
| Class: | Design Error |
| CVE: |
CVE-2012-4418 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2012 12:00AM |
| Updated: | Oct 11 2012 07:40PM |
| Credit: | Juraj Somorovsky, Andreas Mayer, Meiko Jensen, Marco Kampmann and Joerg Schwen |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Apache Axis2 XML Signature Wrapping Security Vulnerability
Apache Axis2 is prone to a security vulnerability involving XML signature wrapping.
Successful exploits may allow unauthenticated attackers to construct specially crafted messages that can be successfully verified and contain arbitrary content. This may aid in further attacks.
Apache Axis2 is prone to a security vulnerability involving XML signature wrapping.
Successful exploits may allow unauthenticated attackers to construct specially crafted messages that can be successfully verified and contain arbitrary content. This may aid in further attacks.
Exploit / POC
Apache Axis2 XML Signature Wrapping Security Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache Axis2 XML Signature Wrapping Security Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Apache Axis2 XML Signature Wrapping Security Vulnerability
References:
References:
- Apache AXIS2 Homepage (Apache)