Apache CXF WS-SecurityPolicy Authentication Bypass Vulnerability
BID:57876
Info
Apache CXF WS-SecurityPolicy Authentication Bypass Vulnerability
| Bugtraq ID: | 57876 |
| Class: | Design Error |
| CVE: |
CVE-2013-0239 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 08 2013 12:00AM |
| Updated: | Mar 27 2013 11:36AM |
| Credit: | Reported by the vendor |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Apache CXF WS-SecurityPolicy Authentication Bypass Vulnerability
Apache CXF is prone to an authentication-bypass vulnerability.
Remote attackers can exploit this issue to bypass the authentication mechanism and gain unauthorized access.
Versions prior to Apache CXF 2.7.3, 2.6.6, and 2.5.9 are vulnerable.
Apache CXF is prone to an authentication-bypass vulnerability.
Remote attackers can exploit this issue to bypass the authentication mechanism and gain unauthorized access.
Versions prior to Apache CXF 2.7.3, 2.6.6, and 2.5.9 are vulnerable.
Exploit / POC
Solution / Fix
Apache CXF WS-SecurityPolicy Authentication Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.