CVE Vulnerabilities

CVE-2009-0217

Published: Jul 14, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits.

Affected Software

NameVendorStart VersionEnd Version
Websphere_application_serverIbm6.0 (including)6.0 (including)
Websphere_application_serverIbm6.0.0.1 (including)6.0.0.1 (including)
Websphere_application_serverIbm6.0.0.2 (including)6.0.0.2 (including)
Websphere_application_serverIbm6.0.0.3 (including)6.0.0.3 (including)
Websphere_application_serverIbm6.0.1 (including)6.0.1 (including)
Websphere_application_serverIbm6.0.1.1 (including)6.0.1.1 (including)
Websphere_application_serverIbm6.0.1.2 (including)6.0.1.2 (including)
Websphere_application_serverIbm6.0.1.3 (including)6.0.1.3 (including)
Websphere_application_serverIbm6.0.1.5 (including)6.0.1.5 (including)
Websphere_application_serverIbm6.0.1.7 (including)6.0.1.7 (including)
Websphere_application_serverIbm6.0.1.9 (including)6.0.1.9 (including)
Websphere_application_serverIbm6.0.1.11 (including)6.0.1.11 (including)
Websphere_application_serverIbm6.0.1.13 (including)6.0.1.13 (including)
Websphere_application_serverIbm6.0.1.15 (including)6.0.1.15 (including)
Websphere_application_serverIbm6.0.1.17 (including)6.0.1.17 (including)
Websphere_application_serverIbm6.0.2 (including)6.0.2 (including)
Websphere_application_serverIbm6.0.2.1 (including)6.0.2.1 (including)
Websphere_application_serverIbm6.0.2.2 (including)6.0.2.2 (including)
Websphere_application_serverIbm6.0.2.3 (including)6.0.2.3 (including)
Websphere_application_serverIbm6.0.2.10 (including)6.0.2.10 (including)
Websphere_application_serverIbm6.0.2.11 (including)6.0.2.11 (including)
Websphere_application_serverIbm6.0.2.12 (including)6.0.2.12 (including)
Websphere_application_serverIbm6.0.2.13 (including)6.0.2.13 (including)
Websphere_application_serverIbm6.0.2.14 (including)6.0.2.14 (including)
Websphere_application_serverIbm6.0.2.15 (including)6.0.2.15 (including)
Websphere_application_serverIbm6.0.2.16 (including)6.0.2.16 (including)
Websphere_application_serverIbm6.0.2.17 (including)6.0.2.17 (including)
Websphere_application_serverIbm6.0.2.18 (including)6.0.2.18 (including)
Websphere_application_serverIbm6.0.2.19 (including)6.0.2.19 (including)
Websphere_application_serverIbm6.0.2.20 (including)6.0.2.20 (including)
Websphere_application_serverIbm6.0.2.21 (including)6.0.2.21 (including)
Websphere_application_serverIbm6.0.2.22 (including)6.0.2.22 (including)
Websphere_application_serverIbm6.0.2.23 (including)6.0.2.23 (including)
Websphere_application_serverIbm6.0.2.24 (including)6.0.2.24 (including)
Websphere_application_serverIbm6.0.2.25 (including)6.0.2.25 (including)
Websphere_application_serverIbm6.0.2.28 (including)6.0.2.28 (including)
Websphere_application_serverIbm6.0.2.29 (including)6.0.2.29 (including)
Websphere_application_serverIbm6.0.2.30 (including)6.0.2.30 (including)
Websphere_application_serverIbm6.0.2.31 (including)6.0.2.31 (including)
Websphere_application_serverIbm6.0.2.32 (including)6.0.2.32 (including)
Websphere_application_serverIbm6.0.2.33 (including)6.0.2.33 (including)
Websphere_application_serverIbm6.1 (including)6.1 (including)
Websphere_application_serverIbm6.1.0 (including)6.1.0 (including)
Websphere_application_serverIbm6.1.0.0 (including)6.1.0.0 (including)
Websphere_application_serverIbm6.1.0.1 (including)6.1.0.1 (including)
Websphere_application_serverIbm6.1.0.2 (including)6.1.0.2 (including)
Websphere_application_serverIbm6.1.0.3 (including)6.1.0.3 (including)
Websphere_application_serverIbm6.1.0.4 (including)6.1.0.4 (including)
Websphere_application_serverIbm6.1.0.5 (including)6.1.0.5 (including)
Websphere_application_serverIbm6.1.0.6 (including)6.1.0.6 (including)
Websphere_application_serverIbm6.1.0.7 (including)6.1.0.7 (including)
Websphere_application_serverIbm6.1.0.8 (including)6.1.0.8 (including)
Websphere_application_serverIbm6.1.0.9 (including)6.1.0.9 (including)
Websphere_application_serverIbm6.1.0.10 (including)6.1.0.10 (including)
Websphere_application_serverIbm6.1.0.11 (including)6.1.0.11 (including)
Websphere_application_serverIbm6.1.0.12 (including)6.1.0.12 (including)
Websphere_application_serverIbm6.1.0.13 (including)6.1.0.13 (including)
Websphere_application_serverIbm6.1.0.14 (including)6.1.0.14 (including)
Websphere_application_serverIbm6.1.0.15 (including)6.1.0.15 (including)
Websphere_application_serverIbm6.1.0.16 (including)6.1.0.16 (including)
Websphere_application_serverIbm6.1.0.17 (including)6.1.0.17 (including)
Websphere_application_serverIbm6.1.0.18 (including)6.1.0.18 (including)
Websphere_application_serverIbm6.1.0.19 (including)6.1.0.19 (including)
Websphere_application_serverIbm6.1.0.20 (including)6.1.0.20 (including)
Websphere_application_serverIbm6.1.0.21 (including)6.1.0.21 (including)
Websphere_application_serverIbm6.1.0.22 (including)6.1.0.22 (including)
Websphere_application_serverIbm6.1.0.23 (including)6.1.0.23 (including)
Websphere_application_serverIbm7.0 (including)7.0 (including)
Websphere_application_serverIbm7.0.0.1 (including)7.0.0.1 (including)
MonoMono_project1.2.1 (including)1.2.1 (including)
MonoMono_project1.2.2 (including)1.2.2 (including)
MonoMono_project1.2.3 (including)1.2.3 (including)
MonoMono_project1.2.4 (including)1.2.4 (including)
MonoMono_project1.2.5 (including)1.2.5 (including)
MonoMono_project1.2.6 (including)1.2.6 (including)
MonoMono_project1.9 (including)1.9 (including)
MonoMono_project2.0 (including)2.0 (including)
Application_serverOracle10.1.2.3 (including)10.1.2.3 (including)
Application_serverOracle10.1.3.4 (including)10.1.3.4 (including)
Application_serverOracle10.1.4.3im (including)10.1.4.3im (including)
Bea_product_suiteOracle8.1-sp6 (including)8.1-sp6 (including)
Bea_product_suiteOracle9.0 (including)9.0 (including)
Bea_product_suiteOracle9.1 (including)9.1 (including)
Bea_product_suiteOracle9.2-mp3 (including)9.2-mp3 (including)
Bea_product_suiteOracle10.0-mp1 (including)10.0-mp1 (including)
Bea_product_suiteOracle10.3 (including)10.3 (including)
Weblogic_server_componentOracle8.1-sp6 (including)8.1-sp6 (including)
Weblogic_server_componentOracle9.0 (including)9.0 (including)
Weblogic_server_componentOracle9.1 (including)9.1 (including)
Weblogic_server_componentOracle9.2-mp3 (including)9.2-mp3 (including)
Weblogic_server_componentOracle10.0-mp1 (including)10.0-mp1 (including)
Weblogic_server_componentOracle10.3 (including)10.3 (including)
Extras for RHEL 4RedHatjava-1.6.0-sun-1:1.6.0.15-1jpp.1.el4*
Extras for RHEL 4RedHatjava-1.6.0-ibm-1:1.6.0.7-1jpp.3.el4*
JBEAP 4.2.0 for RHEL 4RedHatglassfish-javamail-0:1.4.2-0jpp.ep1.5.el4*
JBEAP 4.2.0 for RHEL 4RedHatglassfish-jsf-0:1.2_13-2.1.ep1.el4*
JBEAP 4.2.0 for RHEL 4RedHathibernate3-1:3.2.4-1.SP1_CP09.0jpp.ep1.1.el4*
JBEAP 4.2.0 for RHEL 4RedHathibernate3-annotations-0:3.3.1-1.11.GA_CP02.ep1.el4*
JBEAP 4.2.0 for RHEL 4RedHathibernate3-entitymanager-0:3.3.2-2.5.GA_CP01.ep1.el4*
JBEAP 4.2.0 for RHEL 4RedHatjacorb-0:2.3.0-1jpp.ep1.9.el4*
JBEAP 4.2.0 for RHEL 4RedHatjakarta-commons-logging-jboss-0:1.1-9.ep1.el4*
JBEAP 4.2.0 for RHEL 4RedHatjboss-aop-0:1.5.5-3.CP04.2.ep1.el4*
JBEAP 4.2.0 for RHEL 4RedHatjbossas-0:4.2.0-5.GA_CP08.5.ep1.el4*
JBEAP 4.2.0 for RHEL 4RedHatjboss-common-0:1.2.1-0jpp.ep1.3.el4*
JBEAP 4.2.0 for RHEL 4RedHatjboss-remoting-0:2.2.3-3.SP1.ep1.el4*
JBEAP 4.2.0 for RHEL 4RedHatjboss-seam-0:1.2.1-1.ep1.22.el4*
JBEAP 4.2.0 for RHEL 4RedHatjbossts-1:4.2.3-1.SP5_CP08.1jpp.ep1.1.el4*
JBEAP 4.2.0 for RHEL 4RedHatjbossweb-0:2.0.0-6.CP12.0jpp.ep1.2.el4*
JBEAP 4.2.0 for RHEL 4RedHatjcommon-0:1.0.16-1.1.ep1.el4*
JBEAP 4.2.0 for RHEL 4RedHatjfreechart-0:1.0.13-2.3.1.ep1.el4*
JBEAP 4.2.0 for RHEL 4RedHatjgroups-1:2.4.7-1.ep1.el4*
JBEAP 4.2.0 for RHEL 4RedHatquartz-0:1.5.2-1jpp.patch01.ep1.4.el4*
JBEAP 4.2.0 for RHEL 4RedHatrh-eap-docs-0:4.2.0-6.GA_CP08.ep1.3.el4*
JBEAP 4.2.0 for RHEL 4RedHatxerces-j2-0:2.7.1-9jpp.4.patch_02.1.ep1.el4*
JBEAP 4.2.0 for RHEL 4RedHatxml-security-0:1.3.0-1.3.patch01.ep1.2.el4*
JBEAP 4.2.0 for RHEL 5RedHatglassfish-jsf-0:1.2_13-2.1.ep1.el5*
JBEAP 4.2.0 for RHEL 5RedHathibernate3-1:3.2.4-1.SP1_CP09.0jpp.ep1.2.4.el5*
JBEAP 4.2.0 for RHEL 5RedHathibernate3-annotations-0:3.3.1-1.11GA_CP02.ep1.el5*
JBEAP 4.2.0 for RHEL 5RedHathibernate3-entitymanager-0:3.3.2-2.5.1.ep1.el5*
JBEAP 4.2.0 for RHEL 5RedHatjacorb-0:2.3.0-1jpp.ep1.9.1.el5*
JBEAP 4.2.0 for RHEL 5RedHatjboss-aop-0:1.5.5-3.CP04.2.ep1.el5*
JBEAP 4.2.0 for RHEL 5RedHatjbossas-0:4.2.0-5.GA_CP08.5.2.ep1.el5*
JBEAP 4.2.0 for RHEL 5RedHatjboss-common-0:1.2.1-0jpp.ep1.3.el5.1*
JBEAP 4.2.0 for RHEL 5RedHatjboss-remoting-0:2.2.3-3.SP1.ep1.el5*
JBEAP 4.2.0 for RHEL 5RedHatjboss-seam-0:1.2.1-1.ep1.14.el5*
JBEAP 4.2.0 for RHEL 5RedHatjbossts-1:4.2.3-1.SP5_CP08.1jpp.ep1.1.el5*
JBEAP 4.2.0 for RHEL 5RedHatjbossweb-0:2.0.0-6.CP12.0jpp.ep1.2.el5*
JBEAP 4.2.0 for RHEL 5RedHatjcommon-0:1.0.16-1.1.ep1.el5*
JBEAP 4.2.0 for RHEL 5RedHatjfreechart-0:1.0.13-2.3.1.ep1.el5*
JBEAP 4.2.0 for RHEL 5RedHatjgroups-1:2.4.7-1.ep1.el5*
JBEAP 4.2.0 for RHEL 5RedHatquartz-0:1.5.2-1jpp.patch01.ep1.4.1.el5*
JBEAP 4.2.0 for RHEL 5RedHatrh-eap-docs-0:4.2.0-6.GA_CP08.ep1.3.el5*
JBEAP 4.2.0 for RHEL 5RedHatxml-security-0:1.3.0-1.3.patch01.ep1.2.1.el5*
Red Hat Enterprise Linux 4RedHatxmlsec1-0:1.2.6-3.1*
Red Hat Enterprise Linux 5RedHatjava-1.6.0-openjdk-1:1.6.0.0-1.2.b09.el5*
Red Hat Enterprise Linux 5RedHatxmlsec1-0:1.2.9-8.1.1*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatglassfish-javamail-0:1.4.2-0jpp.ep1.5.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatglassfish-jaxb-0:2.1.4-1.12.patch03.ep1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatglassfish-jsf-0:1.2_13-2.1.ep1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHathibernate3-1:3.2.4-1.SP1_CP09.0jpp.ep1.1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHathibernate3-annotations-0:3.3.1-1.11.GA_CP02.ep1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHathibernate3-entitymanager-0:3.3.2-2.5.GA_CP01.ep1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjacorb-0:2.3.0-1jpp.ep1.9.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjakarta-commons-logging-jboss-0:1.1-9.ep1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjboss-aop-0:1.5.5-3.CP04.2.ep1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjbossas-0:4.3.0-6.GA_CP07.4.ep1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjboss-common-0:1.2.1-0jpp.ep1.3.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjboss-messaging-0:1.4.0-3.SP3_CP09.4.ep1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjboss-remoting-0:2.2.3-3.SP1.ep1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjboss-seam-0:1.2.1-3.JBPAPP_4_3_0_GA.ep1.18.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjboss-seam2-0:2.0.2.FP-1.ep1.21.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjbossts-1:4.2.3-1.SP5_CP08.1jpp.ep1.1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjbossweb-0:2.0.0-6.CP12.0jpp.ep1.2.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjbossws-0:2.0.1-4.SP2_CP07.2.ep1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjbossws-common-0:1.0.0-2.GA_CP05.1.ep1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjbossws-framework-0:2.0.1-1.GA_CP05.1.ep1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjcommon-0:1.0.16-1.1.ep1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjfreechart-0:1.0.13-2.3.1.ep1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjgroups-1:2.4.7-1.ep1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatquartz-0:1.5.2-1jpp.patch01.ep1.4.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatrh-eap-docs-0:4.3.0-6.GA_CP07.ep1.3.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatxerces-j2-0:2.7.1-9jpp.4.patch_02.1.ep1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatxml-security-0:1.3.0-1.3.patch01.ep1.2.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatglassfish-jaxb-0:2.1.4-1.12.patch03.1.ep1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatglassfish-jsf-0:1.2_13-2.1.ep1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHathibernate3-1:3.2.4-1.SP1_CP09.0jpp.ep1.2.4.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHathibernate3-annotations-0:3.3.1-1.11GA_CP02.ep1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHathibernate3-entitymanager-0:3.3.2-2.5.1.ep1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjacorb-0:2.3.0-1jpp.ep1.9.1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjboss-aop-0:1.5.5-3.CP04.2.ep1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjbossas-0:4.3.0-6.GA_CP07.4.2.ep1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjboss-common-0:1.2.1-0jpp.ep1.3.el5.1*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjboss-messaging-0:1.4.0-3.SP3_CP09.4.ep1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjboss-remoting-0:2.2.3-3.SP1.ep1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjboss-seam-0:1.2.1-3.JBPAPP_4_3_0_GA.ep1.12.el5.1*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjboss-seam2-0:2.0.2.FP-1.ep1.18.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjbossts-1:4.2.3-1.SP5_CP08.1jpp.ep1.1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjbossweb-0:2.0.0-6.CP12.0jpp.ep1.2.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjbossws-0:2.0.1-4.SP2_CP07.2.1.ep1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjbossws-common-0:1.0.0-2.GA_CP05.1.ep1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjbossws-framework-0:2.0.1-1.GA_CP05.1.ep1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjcommon-0:1.0.16-1.1.ep1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjfreechart-0:1.0.13-2.3.1.ep1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjgroups-1:2.4.7-1.ep1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatquartz-0:1.5.2-1jpp.patch01.ep1.4.1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatrh-eap-docs-0:4.3.0-6.GA_CP07.ep1.3.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatxml-security-0:1.3.0-1.3.patch01.ep1.2.1.el5*
Red Hat Network Satellite Server v 5.3RedHatjava-1.6.0-ibm-1:1.6.0.7-1jpp.3.el4*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.6.0-sun-1:1.6.0.15-1jpp.1.el5*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.6.0-ibm-1:1.6.0.7-1jpp.2.el5*
Libxml-security-javaUbuntuintrepid*
Libxml-security-javaUbuntujaunty*
Libxml-security-javaUbuntuupstream*
MonoUbuntudapper*
MonoUbuntuhardy*
MonoUbuntuintrepid*
MonoUbuntujaunty*
MonoUbuntuupstream*
Openjdk-6Ubuntuhardy*
Openjdk-6Ubuntuintrepid*
Openjdk-6Ubuntujaunty*
Openoffice.orgUbuntudapper*
Openoffice.orgUbuntuhardy*
Openoffice.orgUbuntuintrepid*
Openoffice.orgUbuntujaunty*
Openoffice.orgUbuntukarmic*
Openoffice.orgUbuntuupstream*
Xml-security-cUbuntuhardy*
Xml-security-cUbuntuintrepid*
Xml-security-cUbuntujaunty*
Xml-security-cUbuntuupstream*
Xmlsec1Ubuntudapper*
Xmlsec1Ubuntuhardy*
Xmlsec1Ubuntuintrepid*
Xmlsec1Ubuntujaunty*
Xmlsec1Ubuntukarmic*
Xmlsec1Ubuntulucid*
Xmlsec1Ubuntuupstream*

References