VYPR
Moderate severityNVD Advisory· Published Feb 12, 2015· Updated May 6, 2026

CVE-2015-0227

CVE-2015-0227

Description

Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks."

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.ws.security:wss4jMaven
< 1.6.171.6.17
org.apache.ws.security:wss4jMaven
>= 2.0.0, < 2.022.02
wss4j:wss4jMaven
< 1.6.171.6.17

Affected products

4
  • Apache/Wss4j4 versions
    cpe:2.3:a:apache:wss4j:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:apache:wss4j:*:*:*:*:*:*:*:*range: <=1.6.16
    • cpe:2.3:a:apache:wss4j:2.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:wss4j:2.0.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:apache:wss4j:2.0.1:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

14

News mentions

0

No linked articles in our index yet.