VDB

DEBIAN-CVE-2015-0226

DEBIAN-CVE-2015-0226 PUBLISHED CVSS 7.5 HIGH

Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series of crafted messages. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-2487.

Risk Scores

CVSS 3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
Debian:11wss4j0, 0, 0
Debian:13wss4j0, 0, 0
Debian:12wss4j0, 0, 0
Debian:14wss4j0, 0, 0

Timeline

  • Oct 30, 2017 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›