Wss4j
Vendor:
First CVE: Oct 30, 2014 · Active for 11 years
5
Total CVEs
More Total CVEs than 77% of tracked products
1.0
Avg CVEs / Year
Bottom 1%
6.4
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Wss4j over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 30, 2014
11 years ago
Most Recent CVE
Mar 10, 2021
1,962 days ago
CVE Severity & Scoring
Wss4j5 CVEs
60%
40%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network3 (60.0%)
Unknown2 (40.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (40.0%)
High1 (20.0%)
Unknown2 (40.0%)
User Interaction
None3 (60.0%)
Unknown2 (40.0%)
Required0 (0.0%)
Privileges Required
Low1 (20.0%)
High0 (0.0%)
None2 (40.0%)
Unknown2 (40.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13936HIGH An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet c | Mar 10, 2021 | 8.8 | 40 | NO | NO |
CVE-2011-2487MEDIUM The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack. | Mar 11, 2020 | 5.9 | 22 | NO | NO |
CVE-2015-0226HIGH Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for | Oct 30, 2017 | 7.5 | 21 | NO | NO |
CVE-2014-3623MEDIUM Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML S | Oct 30, 2014 | 5.0 | 18 | NO | NO |
CVE-2015-0227MEDIUM Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks." | Feb 12, 2015 | 5.0 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Wss4j
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.3.1 | 1 | 8.8 | 22.7% | 0 | 0 |
| 2.0.1 | 2 | 6.3 | 6.5% | 0 | 0 |
| 2.0.0 | 2 | 6.3 | 6.5% | 0 | 0 |
| 2.0 | 1 | 7.5 | 5.5% | 0 | 0 |