CVE-2012-5633
Publication date 12 March 2013
Last updated 24 July 2024
Ubuntu priority
Description
The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.
Notes
seth-arnold
I didn't find the WSS4JInInterceptor module in our sources, I don't think our version is affected