VDB
RHSA-2015%3A0236
RHSA-2015%3A0236
PUBLISHED
CVSS 4.300000190734863 MEDIUM
It was found that Apache WSS4J (Web Services Security for Java), as used by Apache CXF with the TransportBinding, did not, by default, properly enforce all security requirements associated with SAML SubjectConfirmation methods. A remote attacker could use this flaw to perform various types of spoofing attacks on web service endpoints secured by WSS4J that rely on SAML for authentication.
Risk Scores
CVSS 2.0
4.300000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Fuse 6.1 | |
| Red Hat | Red Hat JBoss A-MQ 6.1 |
Timeline
- Feb 18, 2015 CVE Published
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- May 14, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2015:0236 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=jboss.fuse&downloadType=securityPatches&version=6.1.0 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1157304 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1165936 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2015/rhsa-2015_0236.json advisory
- https://access.redhat.com/security/cve/CVE-2014-3623 advisory
- https://www.cve.org/CVERecord?id=CVE-2014-3623 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-3623 advisory
- https://access.redhat.com/security/cve/CVE-2014-3625 advisory
- https://www.cve.org/CVERecord?id=CVE-2014-3625 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-3625 advisory