CVE Vulnerabilities

CVE-2013-0239

Improper Authentication

Published: Mar 12, 2013 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request containing a UsernameToken element that lacks a password child element.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Cxf Apache * 2.5.8 (including)
Cxf Apache 2.4.0 (including) 2.4.0 (including)
Cxf Apache 2.4.1 (including) 2.4.1 (including)
Cxf Apache 2.4.2 (including) 2.4.2 (including)
Cxf Apache 2.4.3 (including) 2.4.3 (including)
Cxf Apache 2.4.4 (including) 2.4.4 (including)
Cxf Apache 2.4.5 (including) 2.4.5 (including)
Cxf Apache 2.4.6 (including) 2.4.6 (including)
Cxf Apache 2.4.7 (including) 2.4.7 (including)
Cxf Apache 2.5.0 (including) 2.5.0 (including)
Cxf Apache 2.5.1 (including) 2.5.1 (including)
Cxf Apache 2.5.2 (including) 2.5.2 (including)
Cxf Apache 2.5.3 (including) 2.5.3 (including)
Cxf Apache 2.5.4 (including) 2.5.4 (including)
Cxf Apache 2.5.5 (including) 2.5.5 (including)
Cxf Apache 2.5.6 (including) 2.5.6 (including)
Cxf Apache 2.5.7 (including) 2.5.7 (including)

Potential Mitigations

References