Vulnerability in XMLEncryption Key Transport Mechanism in JBossWS and Apache WSS4J
CVE-2011-2487
5.9MEDIUM
What is CVE-2011-2487?
The key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J is affected by a vulnerability that allows an attacker to execute a Bleichenbacher attack. By exploiting this flaw, an attacker could potentially decrypt sensitive information, which compromises the confidentiality of the data being processed. It is essential for organizations utilizing these products to apply the necessary security patches or updates to mitigate the risks associated with this implementation flaw.
Affected Version(s)
JBossWS unknown
WSS4J before 1.6.5