Vulnerability Bulletins

IBM Security Bulletin: Vulnerabilities in WSS4J affects IBM Cúram (CVE-2015-0226 & CVE-2015-0227 )

   
Affected software IBM
 
IBM Cúram is shipped with a third party library called WSS4J, which is vulnerable to an attack on XML Encryption. WSS4J also fails to properly enforce the requireSignedEncryptedDataElements property which leaves it vulnerable to XML Signature wrapping attacks . CVE(s): CVE-2015-0226 and CVE-2015-0227 Affected product(s) and affected version(s): IBM Cúram Social Program Management 5.2 SP6 IBM Cúram Social Program Management 6.0 SP2 IBM Cúram Social Program

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerabilities_in_wss4j_affects_ibm_c%25C3%25BAram_cve_2015_0226_cve_2015_0227?lang=en_us