CVE-2012-5633
CVE-2012-5633
The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://cxf.apache.org/cve-2012-5633.htmlhttp://osvdb.org/90079http://packetstormsecurity.com/files/120213/Apache-CXF-WS-Security-URIMappingInterceptor-Bypass.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0256.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0257.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0258.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0259.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0726.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0743.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0749.htmlhttp://seclists.org/fulldisclosure/2013/Feb/39http://secunia.com/advisories/51988