Lucene search

K
redhatcveRedhat.comRH:CVE-2017-5656
HistoryApr 25, 2017 - 1:49 p.m.

CVE-2017-5656

2017-04-2513:49:13
redhat.com
access.redhat.com
9

0.003 Low

EPSS

Percentile

65.4%

It was found that the token cacher in Apache cxf uses a flawed way of caching tokens that are associated with the delegation token received from Security Token Service (STS). This vulnerability could allow an attacker to craft a token which could return an identifier corresponding to a cached token for another user.

0.003 Low

EPSS

Percentile

65.4%