CVEs (57)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Apache Netapp3Cxf Oncommand Workflow AutomationOntap ToolsJun 17, 2026 Mar 15, 2024 N/A· v4 9.3 CRITICAL· v3 N/A· v2 A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users...Show more |
A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one...Show more |
A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing or code exfiltration. The vulnerability only applies when the CXFServlet is configured with both the...Show more |
3Apache DebianOracle18Agile Plm Commerce Guided SearchCommerce Platform+15 moreJun 17, 2026 Sep 19, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference e...Show more |
2Apache Oracle5Business Intelligence Communications Element ManagerCommunications Messaging Server+2 moreJun 17, 2026 Jun 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This...Show more |
2Apache Oracle6Business Intelligence Communications Diameter Intelligence HubCommunications Element Manager+3 moreJun 17, 2026 Apr 2, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR)). Instead of sending...Show more |
3Apache NetappOracle6Business Intelligence Communications Messaging ServerCxf+3 moreJun 17, 2026 Nov 12, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, whic...Show more |
3Apache NetappOracle10Communications Diameter Signaling Router Communications Diameter Signaling Router Idih\Communications Element Manager+7 moreJun 17, 2026 Apr 1, 2020 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disa...Show more |
2Apache Redhat10Cxf Jboss Business Rules Management SystemJboss Enterprise Application Platform+7 moreNov 21, 2024 Mar 11, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack. |
2Apache Oracle7Commerce Guided Search Communications Element ManagerCommunications Session Report Manager+4 moreJun 17, 2026 Jan 16, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious ac...Show more |
2Apache Oracle8Commerce Guided Search Communications Diameter Signaling RouterCommunications Element Manager+5 moreJun 17, 2026 Jan 16, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to verify the signature of tokens issued by the service. Typically, the servi...Show more |
2Apache Oracle5Commerce Guided Search CxfEnterprise Manager Base Platform+2 moreJun 17, 2026 Nov 6, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that...Show more |
2Apache Oracle4Commerce Guided Search CxfFlexcube Private Banking+1 moreJun 17, 2026 Nov 6, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility of a denial of service type attack, where a malicious user crafts a mess...Show more |
2Apache Redhat2Cxf Jboss Enterprise Application PlatformJun 17, 2026 Jul 2, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.handler.pkgs", "com.sun.net.ssl.internal.www.protocol");'. When this system property is set, CXF use...Show more |
Apache CXF supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications. It is possible to craft a message attachment header that could lead to a Denial of Service (DoS) attack on a CXF web s...Show more |
The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signature comparison algorithm which may be exploited by sophisticated timing attacks. |
The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apache Abdera Parser which expands XML entities by default which represents...Show more |
The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists the names and absolute URL addresses of the available service endpoints...Show more |
The WS-SP UsernameToken policy in Apache CXF 2.4.5 and 2.5.1 allows remote attackers to bypass authentication by sending an empty UsernameToken as part of a SOAP request. |
Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation tokens, which means that an attacker could craft a token which would return an identifer correspondi...Show more |