Impact
An authentication bypass exists in the DOM security processor of Apache WSS4J that allows attackers to create forged authenticated SOAP messages. By supplying a crafted unsigned SAML sender‑vouches assertion containing an attacker‑controlled key, an unauthenticated remote user can bypass the normal authentication checks and sign a message as if it were a legitimate authenticated party.
Affected Systems
The vulnerability affects versions of Apache WSS4J older than 4.0.2, 3.0.6, and 2.4.4 distributed by the Apache Software Foundation. Any system utilizing these libraries to process SOAP messages that rely on sender‑vouches authentication without requiring signatures may be exposed.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, so the current exploitation likelihood is indeterminate. The attack vector requires an attacker to send HTTP requests that contain a malicious SAML assertion to a service that uses WSS4J for SOAP message validation. This bypass allows the reuse of authorized credentials or the impersonation of an authenticated user, potentially granting unauthorized access to privileged operations.
OpenCVE Enrichment