Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks."
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2015-02-12 08:59
Updated : 2018-10-04 03:29
NVD link : CVE-2015-0227
Mitre link : CVE-2015-0227
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
apache
- wss4j