Skip to content

Improper Authentication in Apache Axis2

Moderate severity GitHub Reviewed Published May 13, 2022 to the GitHub Advisory Database • Updated Jan 27, 2023

Package

maven org.apache.axis2:axis2 (Maven)

Affected versions

< 1.6.4

Patched versions

1.6.4

Description

Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack," a different vulnerability than CVE-2012-4418.

References

Published by the National Vulnerability Database Oct 9, 2012
Published to the GitHub Advisory Database May 13, 2022
Reviewed Jul 13, 2022
Last updated Jan 27, 2023

Severity

Moderate

EPSS score

0.184%
(56th percentile)

Weaknesses

CVE ID

CVE-2012-5351

GHSA ID

GHSA-66rx-gqx3-p98m

Source code

No known source code
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.