CVE Vulnerabilities

CVE-2013-0239

Improper Authentication

Published: Mar 12, 2013 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
6.4 IMPORTANT
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request containing a UsernameToken element that lacks a password child element.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Cxf Apache * 2.5.8 (including)
Cxf Apache 2.4.0 (including) 2.4.0 (including)
Cxf Apache 2.4.1 (including) 2.4.1 (including)
Cxf Apache 2.4.2 (including) 2.4.2 (including)
Cxf Apache 2.4.3 (including) 2.4.3 (including)
Cxf Apache 2.4.4 (including) 2.4.4 (including)
Cxf Apache 2.4.5 (including) 2.4.5 (including)
Cxf Apache 2.4.6 (including) 2.4.6 (including)
Cxf Apache 2.4.7 (including) 2.4.7 (including)
Cxf Apache 2.5.0 (including) 2.5.0 (including)
Cxf Apache 2.5.1 (including) 2.5.1 (including)
Cxf Apache 2.5.2 (including) 2.5.2 (including)
Cxf Apache 2.5.3 (including) 2.5.3 (including)
Cxf Apache 2.5.4 (including) 2.5.4 (including)
Cxf Apache 2.5.5 (including) 2.5.5 (including)
Cxf Apache 2.5.6 (including) 2.5.6 (including)
Cxf Apache 2.5.7 (including) 2.5.7 (including)
Fuse ESB Enterprise 7.1.0 RedHat *
Red Hat JBoss Enterprise Application Platform 6.0 RedHat *
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5 RedHat apache-cxf-0:2.4.9-6.redhat_3.ep6.el5 *
Red Hat JBoss Enterprise Application Platform 6 for RHEL 6 RedHat apache-cxf-0:2.4.9-6.redhat_3.ep6.el6 *
Red Hat JBoss Portal 6.0 RedHat *

Potential Mitigations

References