Apache Santuario XML Security for JAVA XML Signature CVE-2013-2172 Security Bypass Vulnerability
BID:60846
Info
Apache Santuario XML Security for JAVA XML Signature CVE-2013-2172 Security Bypass Vulnerability
| Bugtraq ID: | 60846 |
| Class: | Design Error |
| CVE: |
CVE-2013-2172 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 25 2013 12:00AM |
| Updated: | Oct 26 2015 04:34PM |
| Credit: | James Forshaw, Context Information Security |
| Vulnerable: |
Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Red Hat JBoss Enterprise Web Platform 5 EL6 Red Hat JBoss Enterprise Web Platform 5 EL5 Red Hat JBoss Enterprise Web Platform 5 EL4 Red Hat JBoss Enterprise Application Platform 5 EL6 Red Hat JBoss Enterprise Application Platform 5 EL5 Red Hat JBoss Enterprise Application Platform 5 EL4 Oracle Glassfish Server 3.0.1 Oracle Glassfish Server 2.1.1 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
Apache Santuario XML Security for JAVA XML Signature CVE-2013-2172 Security Bypass Vulnerability
Apache Santuario XML Security for JAVA is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass the signature verification process and perform unauthorized actions.
The following versions are vulnerable:
Apache Santuario XML Security for JAVA 1.4.x prior to 1.4.8
Apache Santuario XML Security for JAVA 1.5.x prior to 1.5.5
Apache Santuario XML Security for JAVA is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass the signature verification process and perform unauthorized actions.
The following versions are vulnerable:
Apache Santuario XML Security for JAVA 1.4.x prior to 1.4.8
Apache Santuario XML Security for JAVA 1.5.x prior to 1.5.5
Exploit / POC
Apache Santuario XML Security for JAVA XML Signature CVE-2013-2172 Security Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache Santuario XML Security for JAVA XML Signature CVE-2013-2172 Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache Santuario XML Security for JAVA XML Signature CVE-2013-2172 Security Bypass Vulnerability
References:
References:
- XML Security Homepage (Apache Software Foundation)