Apache

Cxf

43 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.86%
  • Veröffentlicht 07.07.2014 14:55:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly validate SAML tokens when caching is enabled, which allows remote attackers to gain access via an invalid SAML token.

  • EPSS 0.96%
  • Veröffentlicht 07.07.2014 14:55:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning is enabled and the UsernameToken policy is set to an EncryptedSupportingToken, transmits the UsernameToken in cleartext, which allows remote attackers...

  • EPSS 6.07%
  • Veröffentlicht 08.05.2014 14:29:13
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (/tmp disk consumption) via a large invalid SOAP message.

  • EPSS 6.07%
  • Veröffentlicht 08.05.2014 14:29:13
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (memory consumption) via a large request with the Content-Type set to text/html to a SOAP endpoint, which triggers an error.

  • EPSS 20.3%
  • Veröffentlicht 19.08.2013 23:55:08
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The streaming XML parser in Apache CXF 2.5.x before 2.5.10, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to cause a denial of service (CPU and memory consumption) via crafted XML with a large number of (1) elements, (2) attribut...

  • EPSS 12.29%
  • Veröffentlicht 19.08.2013 23:55:08
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers...

  • EPSS 4.76%
  • Veröffentlicht 12.03.2013 23:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request containing a UsernameToken el...

  • EPSS 2.3%
  • Veröffentlicht 12.03.2013 23:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET requ...

  • EPSS 4.24%
  • Veröffentlicht 05.01.2013 00:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Apache CXF 2.4.5 through 2.4.7, 2.5.1 through 2.5.3, and 2.6.x before 2.6.1, does not properly enforce child policies of a WS-SecurityPolicy 1.1 SupportingToken policy on the client side, which allows remote attackers to bypass the (1) AlgorithmSuite...

  • EPSS 3.75%
  • Veröffentlicht 03.01.2013 01:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impac...