Remote Message Forgery in Apache Axis2 Leading to Authentication Bypass
CVE-2012-5351
Currently unrated
Summary
Apache Axis2 is susceptible to a vulnerability that permits remote attackers to forge messages by utilizing a SAML assertion that omits the Signature element. This flaw facilitates an authentication bypass, enabling unauthorized access. It is crucial for organizations using Apache Axis2 to review and update their security measures to mitigate the risk posed by this vulnerability.
References
Timeline
Vulnerability published
Vulnerability Reserved