Apache
Apache Wss4j: vulnerabilidades y CVE
Apache Wss4j tiene 11 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses6
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-95616 | Alta (7.5) | 0.31% | — | 30 sept 2026 | An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension… |
| CVE-2026-92899 | Media (4.8) | 0.29% | — | 30 sept 2026 | Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can… |
| CVE-2026-92121 | Alta (7.5) | 0.38% | — | 30 sept 2026 | In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set. The WS-SecurityPolicy enforcer uses that flag to decide… |
| CVE-2026-89238 | Crítica (9.1) | 0.23% | — | 30 sept 2026 | WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to… |
| CVE-2026-88920 | Crítica (9.8) | 0.84% | — | 30 sept 2026 | An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an… |
| CVE-2026-85532 | Alta (7.5) | 0.49% | — | 30 sept 2026 | Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically weak keys or excessive CPU and memory consumption when processing crafted… |
| CVE-2020-13936 | Alta (8.8) | 23% | — | 10 mar 2021 | An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications… |
| CVE-2011-2487 | Media (5.9) | 1.8% | — | 11 mar 2020 | The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack. |
| CVE-2015-0226 | Alta (7.5) | 5.5% | — | 30 oct 2017 | Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the… |
| CVE-2015-0227 | Media (5) | 7.5% | — | 12 feb 2015 | Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks." |
| CVE-2014-3623 | Media (5) | 9.2% | — | 30 oct 2014 | Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation method security… |