Impact
Apache WSS4J is susceptible to a child confusion flaw that allows an attacker to subvert the decryption process: a plaintext element supplied by the attacker can be promoted as the decrypted SOAP header. This incorrect header selection undermines confidentiality coverage and may enable a policy bypass, effectively weakening the security guarantees of encrypted messages.
Affected Systems
All versions of Apache WSS4J older than 4.0.2, 3.0.6, or 2.4.4 are affected. The flaw manifests in the handling of EncryptedHeader child elements within the library’s XML security processing.
Risk and Exploitability
The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating limited publicly known exploitation data. Nevertheless, because the flaw operates during SOAP message decryption, remote attackers with network access to services that use WSS4J can supply crafted encrypted messages to trigger the issue. The absence of a CVSS score precludes precise severity ranking, but the potential for confidentiality loss and policy bypass suggests a substantial risk should the vulnerability be exploited.
OpenCVE Enrichment