[ https://issues.apache.org/jira/browse/AXIS2C-1694?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Matthew Kornfield updated AXIS2C-1694: -------------------------------------- Description: Common Vulnerabilities and Exposures assigned an identifier CVE-2012-4418 to the following vulnerability: Name: CVE-2012-4418 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4418 Assigned: 20120821 Reference: http://www.nds.rub.de/media/nds/veroeffentlichungen/2012/08/22/BreakingSAML_3.pdf Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack." was: Common Vulnerabilities and Exposures assigned an identifier CVE-2012-5351 to the following vulnerability: Name: CVE-2012-5351 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5351 Assigned: 20121009 Reference: http://www.nds.rub.de/media/nds/veroeffentlichungen/2012/08/22/BreakingSAML_3.pdf Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack," a different vulnerability than CVE-2012-4418. > CVE-2012-4418 - "XML Signature wrapping attack" > ----------------------------------------------- > > Key: AXIS2C-1694 > URL: https://issues.apache.org/jira/browse/AXIS2C-1694 > Project: Axis2-C > Issue Type: Bug > Reporter: Matthew Kornfield > Priority: Critical > > Common Vulnerabilities and Exposures assigned an identifier CVE-2012-4418 to > the following vulnerability: > Name: CVE-2012-4418 > URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4418 > Assigned: 20120821 > Reference: > http://www.nds.rub.de/media/nds/veroeffentlichungen/2012/08/22/BreakingSAML_3.pdf > Apache Axis2 allows remote attackers to forge messages and bypass > authentication via an "XML Signature wrapping attack." -- This message was sent by Atlassian JIRA (v6.4.14#64029) --------------------------------------------------------------------- To unsubscribe, e-mail: c-dev-unsubscr...@axis.apache.org For additional commands, e-mail: c-dev-h...@axis.apache.org