Known Vulnerabilities for Wss4j by Apache
Listed below are 5 of the newest known vulnerabilities associated with "Wss4j" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-41000 json | Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time ch... | Not Provided | 2026-06-11 | 2026-06-11 |
| CVE-2026-40996 json | Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for valid... | Not Provided | 2026-06-11 | 2026-06-11 |
| CVE-2026-40994 json | Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disable... | Not Provided | 2026-06-11 | 2026-06-11 |
| CVE-2020-13936 json | An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with t... | 8.8 - HIGH | 2021-03-10 | 2023-11-07 |
| CVE-2015-0227 json | Not Provided | 2015-02-12 | 2026-05-06 | |
| CVE-2015-0226 json | Not Provided | 2017-10-30 | 2025-04-20 | |
| CVE-2014-3623 json | Not Provided | 2014-10-30 | 2026-05-06 | |
| CVE-2011-2487 json | The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susc... | 5.9 - MEDIUM | 2020-03-11 | 2023-02-13 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Wss4j | 2.3.1 | |||
| Application | Apache | Wss4j | 2.2.1 | |||
| Application | Apache | Wss4j | 2.2.0 | |||
| Application | Apache | Wss4j | 2.1.9 | |||
| Application | Apache | Wss4j | 2.1.8 | |||
| Application | Apache | Wss4j | 2.1.7 | |||
| Application | Apache | Wss4j | 2.1.6 | |||
| Application | Apache | Wss4j | 2.1.5 | |||
| Application | Apache | Wss4j | 2.1.4 | |||
| Application | Apache | Wss4j | 2.1.3 | |||
| Application | Apache | Wss4j | 2.1.2 | |||
| Application | Apache | Wss4j | 2.1.12 | |||
| Application | Apache | Wss4j | 2.1.11 | |||
| Application | Apache | Wss4j | 2.1.10 | |||
| Application | Apache | Wss4j | 2.1.1 | |||
| Application | Apache | Wss4j | 2.1.0 | |||
| Application | Apache | Wss4j | 2.0.9 | |||
| Application | Apache | Wss4j | 2.0.8 | |||
| Application | Apache | Wss4j | 2.0.7 | |||
| Application | Apache | Wss4j | 2.0.6 |