Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3177
HistoryDec 28, 2016 - 3:45 a.m.

Cross-site Scripting (XSS)

2016-12-2803:45:07
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17

EPSS

0.002

Percentile

52.0%

Apache CXF HTTP transport is vulnerable to cross-site scripting (XSS) attacks. It exists when a request URL contains unexpected matrix parameters. Apache CXF HTTP transport uses FormattedServiceListWriter to provide an HTML page which lists the names and absolute URL addresses of the available service endpoints. If the unexpected matrix parameters have been injected into the request URL then these matrix parameters will find their way back to the client in the services list page which represents an XSS risk to the client.

References