Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-12419


Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to somehow steal an authorization code issued to another client, then they could exploit this vulnerability to obtain an access token for the other client.


Published

2019-11-06T21:15:11.243

Last Modified

2024-11-21T04:22:48.197

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-863

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache cxf < 3.2.11 Yes
Application apache cxf < 3.3.4 Yes
Application oracle commerce_guided_search 11.3.2 Yes
Application oracle enterprise_manager_base_platform 13.2.1.0 Yes
Application oracle flexcube_private_banking 12.0.0 Yes
Application oracle flexcube_private_banking 12.1.0 Yes
Application oracle retail_order_broker 15.0 Yes

References