CVE-2014-3623: Apache Cxf

Medium severity, CVSS 5.0. EPSS: 9.2% chance of exploitation in the next 30 days.

Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers to conduct spoofing attacks via unspecified vectors.

Affected products

  • Apache Cxf: from 2.7.0, up to and including 2.7.13; from 3.0.0, before 3.0.2 (fixed in 3.0.2)
  • Apache WSS4J: before 1.6.17 (fixed in 1.6.17); from 2.0.0, before 2.0.2 (fixed in 2.0.2)

Published 2014-10-30. Last modified 2026-06-17.