VDB
RHSA-2012%3A1559
RHSA-2012%3A1559
PUBLISHED
CVSS 5.800000190734863 MEDIUM
Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and attack vectors.
Risk Scores
CVSS 2.0
5.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | JBoss Enterprise BRMS Platform 5.3 |
Timeline
- Dec 13, 2012 CVE Published
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- May 14, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2012:1559 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=brms&downloadType=securityPatches&version=5.3.0 advisory
- http://cxf.apache.org/cve-2012-2379.html advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2012/rhsa-2012_1559.json advisory
- https://access.redhat.com/security/cve/CVE-2012-2379 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2012-2379 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=826534 issue
- https://www.cve.org/CVERecord?id=CVE-2012-2379 advisory