VDB
RHSA-2013%3A0953
RHSA-2013%3A0953
PUBLISHED
CVSS 7.800000190734863 HIGH
A flaw was found in JBoss web services where the services used a weak symmetric encryption protocol, PKCS#1 v1.5. An attacker could use this weakness in chosen-ciphertext attacks to recover the symmetric key and conduct further attacks.
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Portal 5.2 |
Timeline
- Jun 18, 2013 CVE Published
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- May 14, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2013:0953 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=jbportal&downloadType=securityPatches&version=5.2.2 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=713539 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=737608 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=880443 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2013/rhsa-2013_0953.json advisory
- https://access.redhat.com/security/cve/CVE-2011-2487 advisory
- https://www.cve.org/CVERecord?id=CVE-2011-2487 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2011-2487 advisory
- https://www.nds.ruhr-uni-bochum.de/research/publications/breaking-xml-encryption-pkcs15/ advisory
- https://access.redhat.com/security/cve/CVE-2011-2730 advisory
- https://www.cve.org/CVERecord?id=CVE-2011-2730 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2011-2730 advisory
- https://access.redhat.com/security/cve/CVE-2012-5575 advisory
- https://www.cve.org/CVERecord?id=CVE-2012-5575 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2012-5575 advisory
- http://cxf.apache.org/cve-2012-5575.html advisory
- http://www.nds.ruhr-uni-bochum.de/research/publications/backwards-compatibility/ advisory