Moderate severityNVD Advisory· Published Feb 12, 2015· Updated May 6, 2026
CVE-2015-0227
CVE-2015-0227
Description
Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks."
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.ws.security:wss4jMaven | < 1.6.17 | 1.6.17 |
org.apache.ws.security:wss4jMaven | >= 2.0.0, < 2.02 | 2.02 |
wss4j:wss4jMaven | < 1.6.17 | 1.6.17 |
Affected products
4Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
14- ws.apache.org/wss4j/advisories/CVE-2015-0227.txt.ascnvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-6r5v-hp32-fjqwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2015-0227ghsaADVISORY
- rhn.redhat.com/errata/RHSA-2015-0773.htmlnvdWEB
- rhn.redhat.com/errata/RHSA-2015-0846.htmlnvdWEB
- rhn.redhat.com/errata/RHSA-2015-0847.htmlnvdWEB
- rhn.redhat.com/errata/RHSA-2015-0848.htmlnvdWEB
- rhn.redhat.com/errata/RHSA-2015-0849.htmlnvdWEB
- rhn.redhat.com/errata/RHSA-2015-1176.htmlnvdWEB
- rhn.redhat.com/errata/RHSA-2015-1177.htmlnvdWEB
- exchange.xforce.ibmcloud.com/vulnerabilities/100837nvdWEB
- support.hpe.com/hpsc/doc/public/displaynvdWEB
- www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlnvdWEB
- www.securityfocus.com/bid/72557nvd
News mentions
0No linked articles in our index yet.