Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3928
HistoryApr 19, 2017 - 3:13 a.m.

Information Disclosure

2017-04-1903:13:44
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.003 Low

EPSS

Percentile

65.4%

Apache cxf-rt-ws-security is vulnerable to information disclosure. A malicious user can pass a malicious delegation token to the application, causing the application to return a cached token from another user.

References

0.003 Low

EPSS

Percentile

65.4%