CVE Vulnerabilities

CVE-2010-3300

Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking

Published: Jun 22, 2021 | Modified: Jun 25, 2021
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

It was found that all OWASP ESAPI for Java up to version 2.0 RC2 are vulnerable to padding oracle attacks.

Weakness

The product uses obfuscation or encryption of inputs that should not be mutable by an external actor, but the product does not use integrity checks to detect if those inputs have been modified.

Affected Software

Name Vendor Start Version End Version
Enterprise_security_api_for_java Owasp * 2.0 (excluding)
Enterprise_security_api_for_java Owasp 2.0 (including) 2.0 (including)
Enterprise_security_api_for_java Owasp 2.0-rc1 (including) 2.0-rc1 (including)

Potential Mitigations

References