The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Openoffice | — | Upgrade Apache OpenOffice to the latest version | Sep 12, 2025 | Jul 14, 2009 |
| Centos_linux | — | Upgrade java-1.6.0-openjdk-develUpgrade java-1.6.0-openjdk-javadocUpgrade xmlsec1-nss-develUpgrade xmlsec1-gnutlsUpgrade xmlsec1-openssl-develUpgrade java-1.6.0-openjdkUpgrade java-1.6.0-openjdk-demoUpgrade xmlsec1Upgrade xmlsec1-nssUpgrade xmlsec1-develUpgrade xmlsec1-opensslUpgrade xmlsec1-gnutls-develUpgrade java-1.6.0-openjdk-src | Dec 1, 2016 | Jul 14, 2009 |
| Debian | — | Upgrade xmlsec1Upgrade monoUpgrade xml-security-c | Jul 30, 2024 | Jul 14, 2009 |
| Freebsd | — | Upgrade openoffice.orgUpgrade mono | Dec 10, 2025 | Jul 29, 2009 |
| Gentoo Linux | — | Upgrade app-office/openoffice-bin.Upgrade dev-lang/mono.Upgrade dev-util/mono-debugger.Upgrade app-office/libreoffice-bin.Upgrade app-office/openoffice.Upgrade app-office/libreoffice. | Oct 30, 2017 | Jul 14, 2009 |
| Hpux | — | Update Jre14.JRE14-PA11 to the latest versionUpdate Jdk15.JDK15-PA20W to the latest versionUpdate Jre60.JRE60-PA20-HS to the latest versionUpdate Jre15.JRE15-IPF64-HS to the latest versionUpdate Jre60.JRE60-IPF64 to the latest versionUpdate Jre60.JRE60-PA20W-HS to the latest versionUpdate Jre15.JRE15-COM to the latest versionUpdate Jdk60.JDK60-PA20W to the latest versionUpdate Jre15.JRE15-IPF32-HS to the latest versionUpdate Jdk60.JDK60-PA20 to the latest versionUpdate Jre60.JRE60-COM to the latest versionUpdate Jdk60.JDK60-IPF32 to the latest versionUpdate Jre14.JRE14-IPF32 to the latest versionUpdate Jdk15.JDK15-IPF64 to the latest versionUpdate Jdk14.JDK14-PA20W to the latest versionUpdate Jre14.JRE14-IPF32-HS to the latest versionUpdate Jdk60.JDK60-COM to the latest versionUpdate Jdk14.JDK14-COM to the latest versionUpdate Jre14.JRE14-IPF64 to the latest versionUpdate Jre14.JRE14-PA20W to the latest versionUpdate Jdk15.JDK15-PA20 to the latest versionUpdate Jdk14.JDK14-PA11 to the latest versionUpdate Jre15.JRE15-PA20W to the latest versionUpdate Jdk14.JDK14-PA20 to the latest versionUpdate Jre14.JRE14-PA11-HS to the latest versionUpdate Jre14.JRE14-PA20W-HS to the latest versionUpdate Jre15.JRE15-IPF32 to the latest versionUpdate Jre15.JRE15-PA20-HS to the latest versionUpdate Jre60.JRE60-PA20W to the latest versionUpdate Jre14.JRE14-COM to the latest versionUpdate Jdk15.JDK15-COM to the latest versionUpdate Jre60.JRE60-PA20 to the latest versionUpdate Jre14.JRE14-PA20 to the latest versionUpdate Jdk15.JDK15-IPF32 to the latest versionUpdate Jdk14.JDK14-IPF64 to the latest versionUpdate Jre60.JRE60-IPF64-HS to the latest versionUpdate Jdk60.JDK60-IPF64 to the latest versionUpdate Jre15.JRE15-PA20 to the latest versionUpdate Jre60.JRE60-IPF32 to the latest versionUpdate Jre15.JRE15-PA20W-HS to the latest versionUpdate Jre14.JRE14-PA20-HS to the latest versionUpdate Jdk14.JDK14-IPF32 to the latest versionUpdate Jre14.JRE14-IPF64-HS to the latest versionUpdate Jre15.JRE15-IPF64 to the latest versionUpdate Jre60.JRE60-IPF32-HS to the latest version | Aug 11, 2017 | Jul 14, 2009 |
| Ibm Was | — | Upgrade to minimal fix pack levels as required by interim fixes and then apply latest Interim Fix. | Apr 27, 2018 | Jul 14, 2009 |
| Oracle_linux | — | Upgrade java-1.6.0-openjdk-srcUpgrade java-1.6.0-openjdk-demoUpgrade java-1.6.0-openjdk-javadocUpgrade java-1.6.0-openjdkUpgrade java-1.6.0-openjdk-devel | Oct 16, 2024 | Jul 14, 2009 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Jul 14, 2009 |
| Suse | — | Upgrade monodoc-coreUpgrade mono-webUpgrade mono-jscriptUpgrade mono-coreUpgrade mono-data-sybaseUpgrade mono-data-oracleUpgrade mono-develUpgrade java-1_6_0-ibm-pluginUpgrade java-1_6_0-ibm-jdbcUpgrade mono-winformsUpgrade java-1_6_0-ibm-alsa-x86Upgrade java-1_6_0-ibm-fontsUpgrade java-1_6_0-ibm-alsaUpgrade mono-winfxcoreUpgrade mono-data-postgresqlUpgrade java-1_6_0-ibmUpgrade mono-wcfUpgrade mono-nunitUpgrade bytefx-data-mysqlUpgrade mono-data-firebirdUpgrade mono-dataUpgrade mono-extrasUpgrade mono-data-sqliteUpgrade mono-locale-extrasUpgrade java-1_6_0-ibm-x86 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade icedtea6-pluginUpgrade libmono-system-web1.0-cilUpgrade libmono-security2.0-cilUpgrade openoffice.org-coreUpgrade openjdk-6-jreUpgrade openjdk-6-jre-libUpgrade libmono-security1.0-cilUpgrade libmono-system-web2.0-cil | Nov 8, 2024 | Jul 14, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub