org.apache.ws.security:wss4j@1.6.16 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the org.apache.ws.security:wss4j package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Use of a Risky Cryptographic Algorithm

org.apache.ws.security:wss4j Affected versions of the package use a Risky Cryptographic Algorithm. The PKCS#1 v1.5 Key Transport Algorithm is used to encrypt symmetric keys as part of WS-Security. WSS4J can leak information about where a particular decryption operation fails.

[1.6.0,1.6.17)
  • M
Access Restriction Bypass

org.apache.ws.security:wss4j Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks."

[,1.6.17)