Apache CXF SAML Tokens Validation Security Bypass Vulnerability
BID:68441
Info
Apache CXF SAML Tokens Validation Security Bypass Vulnerability
| Bugtraq ID: | 68441 |
| Class: | Access Validation Error |
| CVE: |
CVE-2014-0034 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 07 2014 12:00AM |
| Updated: | May 12 2015 07:47PM |
| Credit: | Reported by the vendor |
| Vulnerable: |
Redhat JBoss Enterprise Application Platform 6.2.4 Redhat JBoss Enterprise Application Platform 6.2 EL6 Redhat JBoss Enterprise Application Platform 6.2 EL5 Redhat JBoss Enterprise Application Platform 6 EL6 Redhat JBoss Enterprise Application Platform 6 EL5 Redhat JBoss BRMS 6.0.3 Redhat Jboss Bpm Suite 6.0.3 Redhat Jboss Bpm Suite 6.0.1 Redhat Jboss Bpm Suite 6.0.0 Apache Apache CXF 2.7.8 Apache Apache CXF 2.6.11 Apache Apache CXF 2.6.2 Apache Apache CXF 2.6.1 Apache Apache CXF 2.6 Apache Apache CXF 2.7.4 Apache Apache CXF 2.7.3 Apache Apache CXF 2.7.2 Apache Apache CXF 2.6.7 Apache Apache CXF 2.6.6 Apache Apache CXF 2.6.5 |
| Not Vulnerable: |
Redhat JBoss BRMS 6.1 Redhat Jboss Bpm Suite 6.1 Apache Apache CXF 2.7.9 Apache Apache CXF 2.6.12 |
Discussion
Apache CXF SAML Tokens Validation Security Bypass Vulnerability
Apache CXF is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and gain unauthorized access; this may aid in launching further attacks.
The following versions are affected:
Apache CXF 2.6.x prior to 2.6.12
Apache CXF 2.7.x prior to 2.7.9
Apache CXF is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and gain unauthorized access; this may aid in launching further attacks.
The following versions are affected:
Apache CXF 2.6.x prior to 2.6.12
Apache CXF 2.7.x prior to 2.7.9
Exploit / POC
Apache CXF SAML Tokens Validation Security Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache CXF SAML Tokens Validation Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.