CVE-2010-3300

It was found that all OWASP ESAPI for Java up to version 2.0 RC2 are vulnerable to padding oracle attacks.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:owasp:enterprise_security_api_for_java:*:*:*:*:*:*:*:*
cpe:2.3:a:owasp:enterprise_security_api_for_java:2.0:-:*:*:*:*:*:*
cpe:2.3:a:owasp:enterprise_security_api_for_java:2.0:rc1:*:*:*:*:*:*

History

25 Jun 2021, 17:38

Type Values Removed Values Added
References (MISC) https://www.usenix.org/legacy/events/woot10/tech/full_papers/Rizzo.pdf - (MISC) https://www.usenix.org/legacy/events/woot10/tech/full_papers/Rizzo.pdf - Third Party Advisory
References (MISC) https://seclists.org/oss-sec/2010/q3/357 - (MISC) https://seclists.org/oss-sec/2010/q3/357 - Mailing List, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 5.9
CPE cpe:2.3:a:owasp:enterprise_security_api_for_java:*:*:*:*:*:*:*:*
cpe:2.3:a:owasp:enterprise_security_api_for_java:2.0:-:*:*:*:*:*:*
cpe:2.3:a:owasp:enterprise_security_api_for_java:2.0:rc1:*:*:*:*:*:*
CWE CWE-649

22 Jun 2021, 12:20

Type Values Removed Values Added
New CVE

Information

Published : 2021-06-22 12:15

Updated : 2023-12-10 13:55


NVD link : CVE-2010-3300

Mitre link : CVE-2010-3300

CVE.ORG link : CVE-2010-3300


JSON object : View

Products Affected

owasp

  • enterprise_security_api_for_java
CWE
CWE-649

Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking