Vulnerability Bulletins |
IBM Security Bulletin: Vulnerabilities in WSS4J affects IBM Cúram (CVE-2015-0226 & CVE-2015-0227 ) |
|
| Affected software | IBM |
|
IBM Cúram is shipped with a third party library called WSS4J, which is vulnerable to an attack on XML Encryption. WSS4J also fails to properly enforce the requireSignedEncryptedDataElements property which leaves it vulnerable to XML Signature wrapping attacks . CVE(s): CVE-2015-0226 and CVE-2015-0227 Affected product(s) and affected version(s): IBM Cúram Social Program Management 5.2 SP6 IBM Cúram Social Program Management 6.0 SP2 IBM Cúram Social Program More info: https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerabilities_in_wss4j_affects_ibm_c%25C3%25BAram_cve_2015_0226_cve_2015_0227?lang=en_us |
|






