Impact
In the Apache WSS4J streaming (StAX) code, a signature reference that uses the WS‑Security STR‑Transform leaves an internal "inside signed content" flag permanently set. The policy enforcer checks this flag to decide whether later parts of the message must be validated. When the flag remains set, the enforcer stops evaluating SignedParts and SignedElements for the rest of the message, so a policy that requires the SOAP Body to be signed is satisfied even if the Body contains no signature. Signature verification itself is unchanged, but the policy is incorrectly considered satisfied, allowing an attacker to perform XML Signature Wrapping attacks.
Affected Systems
This flaw applies to the streaming implementation of Apache WSS4J provided by Apache Software Foundation. Versions older than 4.0.2 for the 4.x line, older than 3.0.6 for the 3.x line, and older than 2.4.4 for the 2.x line are affected. The DOM-based implementation is not impacted.
Risk and Exploitability
An attacker can craft a SOAP message that bypasses signature checks by exploiting the permanently set flag, potentially allowing unauthorized data modification or privilege escalation. No CVSS score is supplied, and the EPSS value is unavailable, so the exploit probability is uncertain. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, requiring only network access to the application that processes SOAP messages with WSS4J.
OpenCVE Enrichment