Remote Message Forgery in Apache Axis2 Leading to Authentication Bypass
CVE-2012-5351

Currently unrated

Key Information:

Vendor

Apache

Status
Vendor
CVE Published:
9 October 2012

What is CVE-2012-5351?

Apache Axis2 is susceptible to a vulnerability that permits remote attackers to forge messages by utilizing a SAML assertion that omits the Signature element. This flaw facilitates an authentication bypass, enabling unauthorized access. It is crucial for organizations using Apache Axis2 to review and update their security measures to mitigate the risk posed by this vulnerability.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.