A flaw was found in the way Apache CXF enforced child policies of WS-SecurityPolicy 1.1 on the client side. In certain circumstances, this could lead a client failing to sign or encrypt certain elements as directed by the security policy, leading to information disclosure and insecure transmission of information.
This has been corrected upstream in versions 2.4.8, 2.5.4, and 2.6.1: http://svn.apache.org/viewvc?view=revision&revision=1337150 External Reference: http://cxf.apache.org/cve-2012-2378.html
Created jbossws-cxf tracking bugs for this issue Affects: fedora-17 [bug 846242]
Acknowledgements: Red Hat would like to thank the Apache CXF project for reporting this issue.
This issue has been addressed in following products: JBEAP 6 for RHEL 5 Via RHSA-2012:1591 https://rhn.redhat.com/errata/RHSA-2012-1591.html
This issue has been addressed in following products: JBEAP 6 for RHEL 6 Via RHSA-2012:1592 https://rhn.redhat.com/errata/RHSA-2012-1592.html
This issue has been addressed in following products: JBoss Enterprise Application Platform 6.0.1 Via RHSA-2012:1594 https://rhn.redhat.com/errata/RHSA-2012-1594.html