VDB
RHSA-2016:1376
RHSA-2016:1376
PUBLISHED
CVSS 7.800000190734863 HIGH
It was found that a prior countermeasure in Apache WSS4J for Bleichenbacher's attack on XML Encryption (CVE-2011-2487) threw an exception that permitted an attacker to determine the failure of the attempted attack, thereby leaving WSS4J vulnerable to the attack. The original flaw allowed a remote attacker to recover the entire plain text form of a symmetric key.
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss SOA Platform 5.3 |
Timeline
- Jun 30, 2016 CVE Published
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- May 14, 2026 CVE Updated
- May 15, 2026 Distribution Patch
- May 15, 2026 Security Advisory
- May 15, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2016:1376 advisory
- https://access.redhat.com/articles/2360521 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1191446 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1243934 issue
- https://www.cve.org/CVERecord?id=CVE-2015-0226 advisory
- https://access.redhat.com/security/cve/CVE-2015-0254 advisory
- https://www.cve.org/CVERecord?id=CVE-2015-0254 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2015-0254 advisory
- https://access.redhat.com/security/cve/CVE-2015-3253 advisory
- https://www.cve.org/CVERecord?id=CVE-2015-3253 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2015-3253 advisory
- http://seclists.org/oss-sec/2015/q3/121 advisory
- https://access.redhat.com/security/cve/CVE-2016-2141 advisory
- https://www.cve.org/CVERecord?id=CVE-2016-2141 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-2510 advisory
- https://access.redhat.com/security/updates/classification/#critical advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=soaplatform&downloadType=securityPatches&version=5.3.1+GA advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1198606 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1310647 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1313589 issue
…and 7 more