VDB

RHSA-2015:0236

RHSA-2015:0236 PUBLISHED CVSS 4.300000190734863 MEDIUM

It was found that Apache WSS4J (Web Services Security for Java), as used by Apache CXF with the TransportBinding, did not, by default, properly enforce all security requirements associated with SAML SubjectConfirmation methods. A remote attacker could use this flaw to perform various types of spoofing attacks on web service endpoints secured by WSS4J that rely on SAML for authentication.

Risk Scores

CVSS 2.0
4.300000190734863

Affected Products

VendorProductVersions
Red HatRed Hat JBoss Fuse 6.1
Red HatRed Hat JBoss A-MQ 6.1

Timeline

  • Feb 18, 2015 CVE Published
  • Apr 30, 2026 Distribution Patch
  • Apr 30, 2026 Distribution Patch
  • Apr 30, 2026 Security Advisory
  • May 14, 2026 CVE Updated
  • May 15, 2026 Security Advisory
  • May 15, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›