![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2013-5679 |
Description: | The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ESAPI) for Java 2.x before 2.1.0 does not properly resist tampering with serialized ciphertext, which makes it easier for remote attackers to bypass intended cryptographic protection mechanisms via an attack against authenticity in the default configuration, involving a null MAC and a zero MAC length. |
Test IDs: | 1.3.6.1.4.1.25623.1.1.10.2015.0064 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2013-5679 BugTraq ID: 62415 http://www.securityfocus.com/bid/62415 http://lists.owasp.org/pipermail/esapi-dev/2013-August/002285.html |