VDB

RHSA-2015%3A0236

RHSA-2015%3A0236 PUBLISHED CVSS 4.300000190734863 MEDIUM

It was found that Apache WSS4J (Web Services Security for Java), as used by Apache CXF with the TransportBinding, did not, by default, properly enforce all security requirements associated with SAML SubjectConfirmation methods. A remote attacker could use this flaw to perform various types of spoofing attacks on web service endpoints secured by WSS4J that rely on SAML for authentication.

Risk Scores

CVSS 2.0
4.300000190734863

Affected Products

VendorProductVersions
Red HatRed Hat JBoss Fuse 6.1
Red HatRed Hat JBoss A-MQ 6.1

Timeline

  • Feb 18, 2015 CVE Published
  • Apr 30, 2026 Distribution Patch
  • Apr 30, 2026 Distribution Patch
  • Apr 30, 2026 Security Advisory
  • Apr 30, 2026 Security Advisory
  • Apr 30, 2026 Security Advisory
  • May 14, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›