Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
5.8
CVE-2012-5786
- EPSS 0.1%
- Published 04.11.2012 22:55:03
- Last modified 11.04.2025 00:51:21
The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field o...
4.3
CVE-2012-3451
- EPSS 9.97%
- Published 24.09.2012 17:55:01
- Last modified 11.04.2025 00:51:21
Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action String that is inconsistent with the message body.
9.8
CVE-2010-2076
- EPSS 7.83%
- Published 19.08.2010 18:00:02
- Last modified 11.04.2025 00:51:21
Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUDDI, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows...