CVE-2014-3623

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
30/10/2014
Last modified:
12/04/2025

Description

Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers to conduct spoofing attacks via unspecified vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:wss4j:*:*:*:*:*:*:*:* 1.6.17 (excluding)
cpe:2.3:a:apache:wss4j:*:*:*:*:*:*:*:* 2.0.0 (including) 2.0.2 (excluding)
cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:* 2.7.0 (including) 2.7.13 (including)
cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:* 3.0.0 (including) 3.0.2 (excluding)


References to Advisories, Solutions, and Tools