Brian Thomason created AXIS2C-1607: -------------------------------------- Summary: CVE-2012-5351 - "Signature exclusion attack," a different vulnerability than CVE-2012-4418 Key: AXIS2C-1607 URL: https://issues.apache.org/jira/browse/AXIS2C-1607 Project: Axis2-C Issue Type: Bug Reporter: Brian Thomason Priority: Critical
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-5351 to the following vulnerability: Name: CVE-2012-5351 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5351 Assigned: 20121009 Reference: http://www.nds.rub.de/media/nds/veroeffentlichungen/2012/08/22/BreakingSAML_3.pdf Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack," a different vulnerability than CVE-2012-4418. -- This message is automatically generated by JIRA. If you think it was sent incorrectly, please contact your JIRA administrators For more information on JIRA, see: http://www.atlassian.com/software/jira --------------------------------------------------------------------- To unsubscribe, e-mail: c-dev-unsubscr...@axis.apache.org For additional commands, e-mail: c-dev-h...@axis.apache.org