CVE Vulnerabilities

CVE-2014-3623

Improper Authentication

Published: Oct 30, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers to conduct spoofing attacks via unspecified vectors.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Wss4jApache*1.6.17 (excluding)
Wss4jApache2.0.0 (including)2.0.2 (excluding)
Red Hat JBoss A-MQ 6.1RedHat*
Red Hat JBoss BPMS 6.0RedHat*
Red Hat JBoss BRMS 6.0RedHat*
Red Hat JBoss Data Virtualization 6.1RedHat*
Red Hat JBoss Enterprise Application Platform 6.3RedHat*
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5RedHatapache-cxf-0:2.7.12-1.SP1_redhat_5.1.ep6.el5*
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5RedHatwss4j-0:1.6.16-2.redhat_3.1.ep6.el5*
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 6RedHatapache-cxf-0:2.7.12-1.SP1_redhat_5.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 6RedHatwss4j-0:1.6.16-2.redhat_3.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 7RedHatapache-cxf-0:2.7.12-1.SP1_redhat_5.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 7RedHatwss4j-0:1.6.16-2.redhat_3.1.ep6.el7*
Red Hat JBoss Fuse 6.1RedHat*

Potential Mitigations

References