{"id":"CVE-2012-5351","aliases":[],"url":"https://o3.security/vulnerability/CVE-2012-5351","summary":"Improper Authentication in Apache Axis2","details":"Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a \"Signature exclusion attack,\" a different vulnerability than CVE-2012-4418. ","published":"2022-05-13T01:01:04Z","modified":"2024-12-05T05:43:04.760338Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.axis2:axis2","fixedVersion":"1.6.4"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2012-5351"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/79487"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuapr2022.html"},{"type":"WEB","url":"http://www.nds.rub.de/media/nds/veroeffentlichungen/2012/08/22/BreakingSAML_3.pdf"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-05T05:43:04.760338Z"}}