VDB
CVE-2012-5633
CVE-2012-5633
PUBLISHED
CVSS 5.800000190734863 MEDIUM
Reported by redhat · Published March 12, 2013
The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.
Risk Scores
CVSS 2.0
5.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | n/a, n/a, n/a |
| Maven | org.apache.cxf:cxf | 0, 0, 0 |
| Maven | org.apache.cxf:cxf-rt-ws-security | 2.5-alpha0, 2.5-alpha0, 2.5-alpha0 |
Timeline
- Mar 12, 2013 CVE Published
- Aug 28, 2017 CVE Updated
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 16, 2023 EPSS Score
References
- 51988 third-party-advisoryx_refsource_SECUNIA
- x_refsource_CONFIRM
- x_refsource_MISC
- 20130208 New security advisories for Apache CXF mailing-listx_refsource_FULLDISC
- RHSA-2013:0256 vendor-advisoryx_refsource_REDHAT
- 90079 vdb-entryx_refsource_OSVDB
- RHSA-2013:0257 vendor-advisoryx_refsource_REDHAT
- x_refsource_CONFIRM
- x_refsource_MISC
- 57874 vdb-entryx_refsource_BID
- x_refsource_CONFIRM
- RHSA-2013:0258 vendor-advisoryx_refsource_REDHAT
- 52183 third-party-advisoryx_refsource_SECUNIA
- RHSA-2013:0749 vendor-advisoryx_refsource_REDHAT
- RHSA-2013:0743 vendor-advisoryx_refsource_REDHAT
- x_refsource_MISC
- x_refsource_CONFIRM
- apachecxf-wssecurity-security-bypass(81980) vdb-entryx_refsource_XF
- RHSA-2013:0259 vendor-advisoryx_refsource_REDHAT
- RHSA-2013:0726 vendor-advisoryx_refsource_REDHAT
…and 16 more