CVE-2011-2487
- EPSS 1.76%
- Veröffentlicht 11.03.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 01:28:23
The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.
CVE-2019-17573
- EPSS 7.06%
- Veröffentlicht 16.01.2020 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:32:33
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into ...
CVE-2019-12423
- EPSS 6.06%
- Veröffentlicht 16.01.2020 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:22:48
Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to verify the signature of tokens issued by the service. Typically, the service obtains the public key from...
CVE-2019-12419
- EPSS 13.84%
- Veröffentlicht 06.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:22:48
Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is...
CVE-2019-12406
- EPSS 6.26%
- Veröffentlicht 06.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:22:46
Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility of a denial of service type attack, where a malicious user crafts a message containing a very large nu...
CVE-2018-8039
- EPSS 10.35%
- Veröffentlicht 02.07.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 04:13:09
It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.handler.pkgs", "com.sun.net.ssl.internal.www.protocol");'. When this system property is set, CXF uses some reflection to try to ma...
CVE-2017-12624
- EPSS 3.7%
- Veröffentlicht 14.11.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Apache CXF supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications. It is possible to craft a message attachment header that could lead to a Denial of Service (DoS) attack on a CXF web service provider. Both JAX-WS a...
CVE-2017-3156
- EPSS 6.32%
- Veröffentlicht 10.08.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signature comparison algorithm which may be exploited by sophisticated timing attacks.
CVE-2016-8739
- EPSS 7.32%
- Veröffentlicht 10.08.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apache Abdera Parser which expands XML entities by default which represents a major XXE risk.
CVE-2016-6812
- EPSS 9.19%
- Veröffentlicht 10.08.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists the names and absolute URL addresses of the available service endpoints. The module calculates the ba...