CVE Vulnerabilities

CVE-2014-0035

Published: Jul 07, 2014 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning is enabled and the UsernameToken policy is set to an EncryptedSupportingToken, transmits the UsernameToken in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.

Affected Software

Name Vendor Start Version End Version
Cxf Apache * 2.6.12
Cxf Apache 2.6.8 2.6.8
Cxf Apache 2.6.0 2.6.0
Cxf Apache 2.6.2 2.6.2
Cxf Apache 2.6.9 2.6.9
Cxf Apache 2.6.5 2.6.5
Cxf Apache 2.6.10 2.6.10
Cxf Apache 2.6.6 2.6.6
Cxf Apache 2.6.3 2.6.3
Cxf Apache 2.6.4 2.6.4
Cxf Apache 2.6.11 2.6.11
Cxf Apache 2.6.1 2.6.1
Cxf Apache 2.6.7 2.6.7

References