CVE-2014-0035

Description

The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning is enabled and the UsernameToken policy is set to an EncryptedSupportingToken, transmits the UsernameToken in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.

Risk Information

Base Score
8.6
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C
EPSS Score
Exploitation Probability
0.956

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2014-0035 are fixed in Apache-CXF-Core 2.6.13Windows
Vulnerabilities CVE-2014-0035 are fixed in Apache-CXF-Core 2.7.10Windows
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 6.0.0Windows
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 6.2.0Windows
Vulnerabilities CVE-2014-0035 are fixed in Apache-CXF-Core for Linux 2.6.13Linux
Vulnerabilities CVE-2014-0035 are fixed in Apache-CXF-Core for Linux 2.7.10Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234