Apache CXF SOAP Action Spoofing Security Bypass Vulnerability
BID:55628
Info
Apache CXF SOAP Action Spoofing Security Bypass Vulnerability
| Bugtraq ID: | 55628 |
| Class: | Design Error |
| CVE: |
CVE-2012-3451 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 20 2012 12:00AM |
| Updated: | Apr 13 2015 09:41PM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
Redhat JBoss Enterprise Web Platform 5 EL6 Redhat JBoss Enterprise Web Platform 5 EL5 Redhat JBoss Enterprise Web Platform 5 EL4 Redhat Jboss Enterprise Soa Platform 5.3.1 Redhat JBoss Enterprise Application Platform 6 Redhat JBoss Enterprise Application Platform 5 EL6 Redhat JBoss Enterprise Application Platform 5 EL5 Redhat JBoss Enterprise Application Platform 5 EL4 Apache Apache CXF 2.6.1 Apache Apache CXF 2.6 Apache Apache CXF 2.5.4 Apache Apache CXF 2.5.3 Apache Apache CXF 2.4.8 Apache Apache CXF 2.4.7 Apache Apache CXF 2.5.2 Apache Apache CXF 2.5.1 Apache Apache CXF 2.4.6 Apache Apache CXF 2.4.5 |
| Not Vulnerable: |
Redhat JBoss Enterprise BRMS Platform 5.3.1 Patch 1 Redhat JBoss Enterprise Application Platform 6.0.1 Apache Apache CXF 2.6.2 Apache Apache CXF 2.5.5 Apache Apache CXF 2.4.9 |
Discussion
Apache CXF SOAP Action Spoofing Security Bypass Vulnerability
Apache CXF is prone to a security vulnerability that may allow attackers to conduct SOAP action spoofing attacks.
Attackers can exploit this issue to spoof a SOAP Action and conduct man-in-the-middle attacks. Successful exploits will cause victims to accept the SOAP Action assuming they are from legitimate requests.
Apache CXF is prone to a security vulnerability that may allow attackers to conduct SOAP action spoofing attacks.
Attackers can exploit this issue to spoof a SOAP Action and conduct man-in-the-middle attacks. Successful exploits will cause victims to accept the SOAP Action assuming they are from legitimate requests.
Exploit / POC
Apache CXF SOAP Action Spoofing Security Bypass Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
Apache CXF SOAP Action Spoofing Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more details.
Solution:
Updates are available. Please see the references for more details.
References
Apache CXF SOAP Action Spoofing Security Bypass Vulnerability
References:
References:
- Apache CXF Homepage (Apache Software Foundation)
- CVE-2012-3451: Apache CXF is vulnerable to SOAP Action spoofing attacks on Docum (Apache)
- Important: JBoss Enterprise SOA Platform 5.3.1 update (Red Hat)
- RHSA-2012:1591-1 JBoss Enterprise Application Platform 6.0.1 update (Red Hat)
- RHSA-2012:1592-1 JBoss Enterprise Application Platform 6.0.1 update (Red Hat)
- RHSA-2012:1594-1 JBoss Enterprise Application Platform 6.0.1 update (Red Hat)
- RHSA-2013:0256-1 JBoss Enterprise Application Platform 5.2.0 security update (Red Hat)
- RHSA-2013:0257-1 JBoss Enterprise Application Platform 5.2.0 security update (Red Hat)
- RHSA-2013:0258-1 JBoss Enterprise Web Platform 5.2.0 security update (Red Hat)
- RHSA-2013:0259-1 JBoss Enterprise Web Platform 5.2.0 security update (Red Hat)
- RHSA-2013:0743-1: JBoss Enterprise BRMS Platform 5.3.1 update (Red Hat)