CVE-2012-5351

EPSS 0.31%

Improper Authentication in Apache Axis2

Published: 5/13/2022Modified: 12/5/2024

Description

Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack," a different vulnerability than CVE-2012-4418.

Affected packages (1)

References (4)