Lucene search

K
githubGitHub Advisory DatabaseGHSA-55J7-F5WF-43M4
HistoryMay 13, 2022 - 1:09 a.m.

Remote web-service operation execution in Apache CXF

2022-05-1301:09:21
CWE-20
GitHub Advisory Database
github.com
15
apache cxf
web service
remote attack

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.002

Percentile

54.6%

Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action String that is inconsistent with the message body.

Affected configurations

Vulners
Node
org.apache.cxfcxfRange2.6.02.6.2
OR
org.apache.cxfcxfRange2.5.02.5.5
OR
org.apache.cxfcxfRange<2.4.9
VendorProductVersionCPE
org.apache.cxfcxf*cpe:2.3:a:org.apache.cxf:cxf:*:*:*:*:*:*:*:*

References

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.002

Percentile

54.6%