VDB
RHSA-2012%3A1593
RHSA-2012%3A1593
PUBLISHED
CVSS 5.800000190734863 MEDIUM
Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and attack vectors.
Risk Scores
CVSS 2.0
5.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss SOA Platform 5.3 |
Timeline
- Dec 18, 2012 CVE Published
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- May 14, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2012:1593 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=soaplatform&downloadType=securityPatches&version=5.3.0+GA advisory
- http://cxf.apache.org/cve-2012-2379.html advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=826534 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2012/rhsa-2012_1593.json advisory
- https://access.redhat.com/security/cve/CVE-2012-2379 advisory
- https://www.cve.org/CVERecord?id=CVE-2012-2379 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2012-2379 advisory