Remote Message Forgery in Apache Axis2 Leading to Authentication Bypass
CVE-2012-5351

Currently unrated

Key Information:

Vendor
Apache
Status
Vendor
CVE Published:
9 October 2012

Summary

Apache Axis2 is susceptible to a vulnerability that permits remote attackers to forge messages by utilizing a SAML assertion that omits the Signature element. This flaw facilitates an authentication bypass, enabling unauthorized access. It is crucial for organizations using Apache Axis2 to review and update their security measures to mitigate the risk posed by this vulnerability.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.