Vulnerabilities (CVE)

Filtered by vendor Apache Subscribe
Filtered by product Wss4j
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-3623 1 Apache 2 Cxf, Wss4j 2021-06-16 5.0 MEDIUM N/A
Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers to conduct spoofing attacks via unspecified vectors.
CVE-2015-0227 1 Apache 1 Wss4j 2018-10-04 5.0 MEDIUM N/A
Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks."