Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A misconfiguration in Spring Web Services’ WS-Security interceptor causes inbound SOAP message validation to skip BSP compliance enforcement, allowing malformed or non-compliant messages to pass through security controls unchecked. Organizations running Spring Web Services versions 3.1.0 through 5.0.1 in SOAP-based integration environments are exposed. The business risk is unauthorized or malformed requests reaching backend services that assume validated, compliant input.

Author

Tech Jacks Solutions