JBoss Web Services W3C XML Encryption Standard Information Disclosure Vulnerability
BID:55770
Info
JBoss Web Services W3C XML Encryption Standard Information Disclosure Vulnerability
| Bugtraq ID: | 55770 |
| Class: | Design Error |
| CVE: |
CVE-2011-1096 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 03 2012 12:00AM |
| Updated: | Feb 26 2013 10:53PM |
| Credit: | Juraj Somorovsky of Ruhr-University Bochum |
| Vulnerable: |
Red Hat JBoss Enterprise Web Platform for RHEL 5 Server 5 Red Hat JBoss Enterprise Web Platform for RHEL 4ES 5 Red Hat JBoss Enterprise Web Platform for RHEL 4AS 5 Red Hat Jboss Enterprise Soa Platform 4.3 CP04 Red Hat Jboss Enterprise Soa Platform 4.3 CP02 Red Hat Jboss Enterprise Soa Platform 4.2 CP04 Red Hat Jboss Enterprise Soa Platform 4.2 CP03 Red Hat Jboss Enterprise Soa Platform 4.3.0 Red Hat Jboss Enterprise Soa Platform 4.2.0 Cp05 Red Hat JBoss Enterprise Portal Platform 4.3.CP06 Red Hat JBoss Enterprise BRMS Platform 5.1 Red Hat JBoss Enterprise Application Platform for RHEL 4ES 5 Red Hat JBoss Enterprise Application Platform for RHEL 4AS 5 Red Hat JBoss Enterprise Application Platform 4.3 EL5 Red Hat JBoss Application Server 7.0 |
| Not Vulnerable: |
Red Hat Jboss Enterprise Soa Platform 4.3.0 Cp05 Red Hat JBoss Enterprise Portal Platform 4.3 CP07 |
Discussion
JBoss Web Services W3C XML Encryption Standard Information Disclosure Vulnerability
JBoss Web Services (JBossWS) is prone to an information disclosure vulnerability due to a design error in the W3C XML Encryption Standard when using the cipher-block chaining (CBC) mode of operation.
Successful exploits may allow an attacker to gain access to sensitive information that may aid in further attacks.
JBoss Web Services (JBossWS) is prone to an information disclosure vulnerability due to a design error in the W3C XML Encryption Standard when using the cipher-block chaining (CBC) mode of operation.
Successful exploits may allow an attacker to gain access to sensitive information that may aid in further attacks.
Exploit / POC
JBoss Web Services W3C XML Encryption Standard Information Disclosure Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
JBoss Web Services W3C XML Encryption Standard Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
JBoss Web Services W3C XML Encryption Standard Information Disclosure Vulnerability
References:
References:
- Bug 681916 - (CVE-2011-1096) CVE-2011-1096 jbossws: Prone to character encoding (Bugzilla)
- JBoss Community Homepage (JBoss Group)
- Important: JBoss Enterprise BRMS Platform 5.3.1 update (Red Hat)
- Important: JBoss Web Services security update (Red Hat)
- JBoss Enterprise Application Platform 4.3.0 CP10 security update (Red Hat)
- RHSA-2012:1330-1: JBoss Enterprise SOA Platform 5.3.0 security update (Red Hat)
- RHSA-2012:1344-1 : JBoss Enterprise Portal Platform 5.2.2 security update (Red Hat)