Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-1954


Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.


Published

2020-04-01T21:15:14.597

Last Modified

2024-11-21T05:11:43.723

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

CVSSv2 Vector

AV:A/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

5.5

Impact Score

2.9

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache cxf < 3.2.13 Yes
Application apache cxf < 3.3.6 Yes
Application oracle communications_diameter_signaling_router ≤ 8.2.2 Yes
Application oracle communications_element_manager ≤ 8.2.2 Yes
Application oracle communications_session_report_manager ≤ 8.2.2 Yes
Application oracle enterprise_manager_base_platform 13.2.1.0 Yes
Application oracle peoplesoft_enterprise_peopletools 8.56 Yes
Application netapp oncommand_workflow_automation - Yes
Application netapp snapmanager - Yes
Application oracle communications_diameter_signaling_router_idih\ ≤ 8.2.2 Yes
Application oracle communications_element_manager ≤ 8.2.2 Yes
Application oracle communications_session_report_manager ≤ 8.2.2 Yes
Application oracle communications_session_route_manager ≤ 8.2.2 Yes
Application oracle enterprise_manager_base_platform 13.2.1.0 Yes
Application oracle peoplesoft_enterprise_peopletools 8.56 Yes

References