The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Openoffice | — | Upgrade Apache OpenOffice to the latest version | Sep 12, 2025 | Jul 14, 2009 |
| Centos_linux | — | Upgrade xmlsec1-develUpgrade xmlsec1-gnutls-develUpgrade java-1.6.0-openjdk-develUpgrade xmlsec1Upgrade java-1.6.0-openjdk-demoUpgrade java-1.6.0-openjdk-srcUpgrade xmlsec1-opensslUpgrade xmlsec1-openssl-develUpgrade java-1.6.0-openjdk-javadocUpgrade xmlsec1-nss-develUpgrade xmlsec1-nssUpgrade java-1.6.0-openjdkUpgrade xmlsec1-gnutls | Dec 1, 2016 | Jul 14, 2009 |
| Debian | — | Upgrade xml-security-cUpgrade monoUpgrade xmlsec1 | Jul 30, 2024 | Jul 14, 2009 |
| Freebsd | — | Upgrade openoffice.orgUpgrade mono | Dec 10, 2025 | Jul 29, 2009 |
| Gentoo Linux | — | Upgrade app-office/libreoffice.Upgrade dev-util/mono-debugger.Upgrade app-office/libreoffice-bin.Upgrade app-office/openoffice-bin.Upgrade app-office/openoffice.Upgrade dev-lang/mono. | Oct 30, 2017 | Jul 14, 2009 |
| Hpux | — | Update Jdk14.JDK14-COM to the latest versionUpdate Jre15.JRE15-IPF32 to the latest versionUpdate Jdk15.JDK15-PA20 to the latest versionUpdate Jdk60.JDK60-COM to the latest versionUpdate Jre60.JRE60-COM to the latest versionUpdate Jre60.JRE60-PA20W-HS to the latest versionUpdate Jre14.JRE14-PA20W-HS to the latest versionUpdate Jre15.JRE15-IPF64-HS to the latest versionUpdate Jre60.JRE60-IPF64 to the latest versionUpdate Jre14.JRE14-IPF32 to the latest versionUpdate Jre14.JRE14-IPF64 to the latest versionUpdate Jre15.JRE15-COM to the latest versionUpdate Jre15.JRE15-PA20W to the latest versionUpdate Jdk15.JDK15-IPF64 to the latest versionUpdate Jdk14.JDK14-PA20 to the latest versionUpdate Jre15.JRE15-PA20-HS to the latest versionUpdate Jdk60.JDK60-IPF32 to the latest versionUpdate Jre15.JRE15-IPF32-HS to the latest versionUpdate Jre14.JRE14-PA20W to the latest versionUpdate Jdk15.JDK15-PA20W to the latest versionUpdate Jre60.JRE60-PA20-HS to the latest versionUpdate Jdk60.JDK60-PA20W to the latest versionUpdate Jre14.JRE14-PA11 to the latest versionUpdate Jre14.JRE14-IPF32-HS to the latest versionUpdate Jdk14.JDK14-PA20W to the latest versionUpdate Jdk14.JDK14-PA11 to the latest versionUpdate Jre14.JRE14-PA11-HS to the latest versionUpdate Jdk60.JDK60-PA20 to the latest versionUpdate Jdk15.JDK15-IPF32 to the latest versionUpdate Jre15.JRE15-PA20 to the latest versionUpdate Jre60.JRE60-IPF64-HS to the latest versionUpdate Jdk60.JDK60-IPF64 to the latest versionUpdate Jre15.JRE15-IPF64 to the latest versionUpdate Jre15.JRE15-PA20W-HS to the latest versionUpdate Jre14.JRE14-PA20-HS to the latest versionUpdate Jre14.JRE14-COM to the latest versionUpdate Jre60.JRE60-IPF32 to the latest versionUpdate Jdk14.JDK14-IPF64 to the latest versionUpdate Jre60.JRE60-IPF32-HS to the latest versionUpdate Jre60.JRE60-PA20W to the latest versionUpdate Jre14.JRE14-PA20 to the latest versionUpdate Jdk15.JDK15-COM to the latest versionUpdate Jre14.JRE14-IPF64-HS to the latest versionUpdate Jre60.JRE60-PA20 to the latest versionUpdate Jdk14.JDK14-IPF32 to the latest version | Aug 11, 2017 | Jul 14, 2009 |
| Ibm Was | — | Upgrade to minimal fix pack levels as required by interim fixes and then apply latest Interim Fix. | Apr 27, 2018 | Jul 14, 2009 |
| Oracle_linux | — | Upgrade java-1.6.0-openjdk-srcUpgrade java-1.6.0-openjdk-demoUpgrade java-1.6.0-openjdk-develUpgrade java-1.6.0-openjdkUpgrade java-1.6.0-openjdk-javadoc | Oct 16, 2024 | Jul 14, 2009 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Jul 14, 2009 |
| Suse | — | Upgrade java-1_6_0-ibm-pluginUpgrade mono-develUpgrade mono-coreUpgrade mono-webUpgrade mono-jscriptUpgrade mono-winformsUpgrade monodoc-coreUpgrade java-1_6_0-ibm-jdbcUpgrade mono-data-oracleUpgrade mono-data-sybaseUpgrade mono-wcfUpgrade java-1_6_0-ibmUpgrade mono-nunitUpgrade java-1_6_0-ibm-fontsUpgrade java-1_6_0-ibm-alsaUpgrade mono-locale-extrasUpgrade bytefx-data-mysqlUpgrade mono-dataUpgrade mono-data-firebirdUpgrade mono-data-sqliteUpgrade mono-winfxcoreUpgrade mono-extrasUpgrade java-1_6_0-ibm-x86Upgrade java-1_6_0-ibm-alsa-x86Upgrade mono-data-postgresql | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade openjdk-6-jre-libUpgrade libmono-security1.0-cilUpgrade libmono-system-web2.0-cilUpgrade openjdk-6-jreUpgrade libmono-security2.0-cilUpgrade libmono-system-web1.0-cilUpgrade openoffice.org-coreUpgrade icedtea6-plugin | Nov 8, 2024 | Jul 14, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub