CVE-2012-4418
Apache Axis2 Vulnerable to XML Signature wrapping attack
EPSS 6.0%
Description
Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."
How to fix CVE-2012-4418
To remediate CVE-2012-4418, upgrade the affected package to a fixed version below.
- Maven/org.apache.axis2:axis2—upgrade to 1.7.9 or later
Is CVE-2012-4418 being exploited?
Moderate — EPSS is 6.0%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 1.7.9