CVE-2012-5351
Improper Authentication in Apache Axis2
EPSS 5.1%
Description
Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack," a different vulnerability than CVE-2012-4418.
How to fix CVE-2012-5351
To remediate CVE-2012-5351, upgrade the affected package to a fixed version below.
- Maven/org.apache.axis2:axis2—upgrade to 1.6.4 or later
Is CVE-2012-5351 being exploited?
Moderate — EPSS is 5.1%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 1.6.4