[ https://issues.apache.org/jira/browse/AXIS2C-1694?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16460357#comment-16460357 ]
Bill Blough commented on AXIS2C-1694: ------------------------------------- The paper cites Axis2 as vulnerable, however it appears that it was referring to the Java version, so it is not clear whether Axis2/C is affected. Need to investigate further to see if this is applicable. > CVE-2012-4418 - "XML Signature wrapping attack" > ----------------------------------------------- > > Key: AXIS2C-1694 > URL: https://issues.apache.org/jira/browse/AXIS2C-1694 > Project: Axis2-C > Issue Type: Bug > Reporter: Matthew Kornfield > Priority: Critical > > Common Vulnerabilities and Exposures assigned an identifier CVE-2012-4418 to > the following vulnerability: > Name: CVE-2012-4418 > URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4418 > Assigned: 20120821 > Reference: > http://www.nds.rub.de/media/nds/veroeffentlichungen/2012/08/22/BreakingSAML_3.pdf > Apache Axis2 allows remote attackers to forge messages and bypass > authentication via an "XML Signature wrapping attack." -- This message was sent by Atlassian JIRA (v7.6.3#76005) --------------------------------------------------------------------- To unsubscribe, e-mail: c-dev-unsubscr...@axis.apache.org For additional commands, e-mail: c-dev-h...@axis.apache.org