Skip to main content

JBoss Enterprise Application Platform Multiple Vulnerabilities

Last Update Date: 31 May 2013 Release Date: 30 May 2013 3475 Views

RISK: Medium Risk

TYPE: Servers - Web Servers

TYPE: Web Servers

Multiple vulnerabilities have been identified in JBoss Enterprise Application Platform.

 

XML encryption backwards compatibility attacks were found against various frameworks, including Apache CXF. An attacker could force a server to use insecure, legacy cryptosystems, even when secure cryptosystems were enabled on endpoints.


Impact

  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

  • JBoss Enterprise Application Platform 5.2.0

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link