CVE-2013-2172

Description

jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to spoof an XML Signature by using the CanonicalizationMethod parameter to specify an arbitrary weak canonicalization algorithm to apply to the SignedInfo part of the Signature.

Risk Information

Base Score
9.1
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
5.394

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2013-5823,CVE-2013-2172 are fixed in Apache - xmlsec 1.4.8Windows
Vulnerabilities CVE-2013-2172 are fixed in Apache - xmlsec 1.5.5Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.6Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.0.4Windows
libxml-security-java security update(DSA-3065-1) libxml-security-java_1.5.6-1_all.debLinux
libxml-security-java security update(DSA-3065-1) libxml-security-java_1.4.5-1+deb7u1_all.debLinux
Vulnerabilities CVE-2013-5823,CVE-2013-2172 are fixed in Apache - xmlsec for Linux 1.4.8Linux
Vulnerabilities CVE-2013-2172 are fixed in Apache - xmlsec for Linux 1.5.5Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234