By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into the web page. Please note that the attack exploits a feature which is not typically not present in modern browsers, who remove dot segments before sending the request. However, Mobile applications may be vulnerable.
2020-01-16T18:15:11.587
2024-11-21T04:32:33.960
Modified
CVSSv3.1: 6.1 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | cxf | ≤ 3.2.12 | Yes |
Application | apache | cxf | < 3.3.5 | Yes |
Application | oracle | commerce_guided_search | 11.3.2 | Yes |
Application | oracle | communications_element_manager | 8.1.1 | Yes |
Application | oracle | communications_element_manager | 8.2.0 | Yes |
Application | oracle | communications_element_manager | 8.2.1 | Yes |
Application | oracle | communications_session_report_manager | 8.1.1 | Yes |
Application | oracle | communications_session_report_manager | 8.2.0 | Yes |
Application | oracle | communications_session_report_manager | 8.2.1 | Yes |
Application | oracle | communications_session_route_manager | 8.1.1 | Yes |
Application | oracle | communications_session_route_manager | 8.2.0 | Yes |
Application | oracle | communications_session_route_manager | 8.2.1 | Yes |
Application | oracle | flexcube_private_banking | 12.0.0 | Yes |
Application | oracle | flexcube_private_banking | 12.1.0 | Yes |
Application | oracle | retail_order_broker | 15.0 | Yes |