← Vulnerability feed

Vulnerability record · CVE-2014-3623 · published 30 October 2014

CVE-2014-3623: Apache wss4j improper authentication vulnerability

Apache · Wss4j

Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers to conduct spoofing attacks via unspecified vectors.

5.0 CVSS 2.0 Medium EPSS 9.2% · top 4.8% CWE-287 · Improper authentication
5.0CVSS 2.0 base score
9.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
30References
17 Jun 2026Last modified by NVD

Description

Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers to conduct spoofing attacks via unspecified vectors.

AV:N/AC:L/Au:N/C:N/I:P/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://rhn.redhat.com/errata/RHSA-2015-0236.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-0675.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-0850.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-0851.html Third Party Advisory
http://seclists.org/oss-sec/2014/q4/437 Mailing ListThird Party Advisory
http://secunia.com/advisories/61909 Third Party Advisory
http://www.securityfocus.com/bid/70736 Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/97754 VDB Entry
https://issues.apache.org/jira/browse/WSS-511 Vendor Advisory
https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.o
https://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.o
https://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.o
https://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.o
https://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.o
https://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.o
http://rhn.redhat.com/errata/RHSA-2015-0236.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-0675.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-0850.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-0851.html Third Party Advisory
http://seclists.org/oss-sec/2014/q4/437 Mailing ListThird Party Advisory
http://secunia.com/advisories/61909 Third Party Advisory
http://www.securityfocus.com/bid/70736 Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/97754 VDB Entry
https://issues.apache.org/jira/browse/WSS-511 Vendor Advisory
https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.o
https://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.o
https://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.o
https://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.o
https://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.o
https://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.o

Track CVE-2014-3623 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-2379Apache cxf vulnerabilityApache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 pol…EPSS 4.1%9.8CVE-2026-68079Apache cxf authentication bypass by capture-replay vulnerabilityIn Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the im…EPSS 0.68%9.8CVE-2026-66909Apache cxf deserialization of untrusted data vulnerabilityApache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in pla…EPSS 1.1%9.8CVE-2026-49875Apache cxf xml external entity (xxe) vulnerabilityApache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configuration…EPSS 0.81%9.8CVE-2026-50628Apache cxf improper input validation vulnerabilityA logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other…EPSS 1.0%9.8CVE-2026-44930Apache cxf ldap injection vulnerabilityAn LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certi…EPSS 0.51%9.8CVE-2025-48913Apache cxf improper input validation vulnerabilityIf untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution cap…EPSS 0.82%9.8CVE-2022-46364Apache cxf server-side request forgery (ssrf) vulnerabilityA SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attack…EPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2014-3623), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.