[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2019-12423":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T14:55:33.319Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":588,"aliases":589,"duplicate_of":9,"upstream":591,"downstream":592,"duplicates":605,"related":606,"reserved_at":9,"published_at":607,"modified_at":608,"state":609,"summary":610,"references_raw":619,"kevs":699,"epss":700,"epss_history":703,"metrics":965,"affected":978},"CVE-2019-12423","Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to verify the signature of tokens issued by the service. Typically, the service obtains the public key from a local keystore (JKS/PKCS12) by specifing the path of the keystore and the alias of the keystore entry. This case is not vulnerable. However it is also possible to obtain the keys from a JWK keystore file, by setting the configuration parameter \"rs.security.keystore.type\" to \"jwk\". For this case all keys are returned in this file \"as is\", including all private key and secret key credentials. This is an obvious security risk if the user has configured the signature keystore file with private or secret key credentials. From CXF 3.3.5 and 3.2.12, it is mandatory to specify an alias corresponding to the id of the key in the JWK file, and only this key is returned. In addition, any private key information is omitted by default. \"oct\" keys, which contain secret keys, are not returned at all.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-522","Insufficiently Protected Credentials","The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.","weakness","Incomplete","Class",[19,23,77,81,156,232,313,367,397,438,497,532,584],{"id":20,"name":21,"techniques":22},"CAPEC-102","Session Sidejacking",[],{"id":24,"name":25,"techniques":26},"CAPEC-474","Signature Spoofing by Key Theft",[27],{"id":28,"name":29,"tactics":30,"countermeasures":34},"T1552.004","Private Keys",[31],{"id":32,"name":33},"TA0031","Credential Access",[35,40,45,49,54,59,63,67,72],{"id":36,"name":37,"tactic":38},"D3-CCSA","Credential Compromise Scope Analysis",{"name":39},"Detect",{"id":41,"name":42,"tactic":43},"D3-CR","Credential Revocation",{"name":44},"Evict",{"id":46,"name":47,"tactic":48},"D3-ANCI","Authentication Cache Invalidation",{"name":44},{"id":50,"name":51,"tactic":52},"D3-DUC","Decoy User Credential",{"name":53},"Deceive",{"id":55,"name":56,"tactic":57},"D3-CH","Credential Hardening",{"name":58},"Harden",{"id":60,"name":61,"tactic":62},"D3-MFA","Multi-factor Authentication",{"name":58},{"id":64,"name":65,"tactic":66},"D3-CRO","Credential Rotation",{"name":58},{"id":68,"name":69,"tactic":70},"D3-RIC","Reissue Credential",{"name":71},"Restore",{"id":73,"name":74,"tactic":75},"D3-CTS","Credential Transmission Scoping",{"name":76},"Isolate",{"id":78,"name":79,"techniques":80},"CAPEC-50","Password Recovery Exploitation",[],{"id":82,"name":83,"techniques":84},"CAPEC-509","Kerberoasting",[85],{"id":86,"name":83,"tactics":87,"countermeasures":89},"T1558.003",[88],{"id":32,"name":33},[90,94,98,102,106,110,114,118,122,124,128,130,132,134,136,138,140,144,148,150,154],{"id":91,"name":92,"tactic":93},"D3-UGLPA","User Geolocation Logon Pattern Analysis",{"name":39},{"id":95,"name":96,"tactic":97},"D3-PMAD","Protocol Metadata Anomaly Detection",{"name":39},{"id":99,"name":100,"tactic":101},"D3-CSPP","Client-server Payload Profiling",{"name":39},{"id":103,"name":104,"tactic":105},"D3-PHDURA","Per Host Download-Upload Ratio Analysis",{"name":39},{"id":107,"name":108,"tactic":109},"D3-NTSA","Network Traffic Signature Analysis",{"name":39},{"id":111,"name":112,"tactic":113},"D3-APCA","Application Protocol Command Analysis",{"name":39},{"id":115,"name":116,"tactic":117},"D3-NTCD","Network Traffic Community Deviation",{"name":39},{"id":119,"name":120,"tactic":121},"D3-RTSD","Remote Terminal Session Detection",{"name":39},{"id":36,"name":37,"tactic":123},{"name":39},{"id":125,"name":126,"tactic":127},"D3-RTA","RPC Traffic Analysis",{"name":39},{"id":41,"name":42,"tactic":129},{"name":44},{"id":46,"name":47,"tactic":131},{"name":44},{"id":50,"name":51,"tactic":133},{"name":53},{"id":55,"name":56,"tactic":135},{"name":58},{"id":60,"name":61,"tactic":137},{"name":58},{"id":64,"name":65,"tactic":139},{"name":58},{"id":141,"name":142,"tactic":143},"D3-TB","Token Binding",{"name":58},{"id":145,"name":146,"tactic":147},"D3-TBA","Token-based Authentication",{"name":58},{"id":68,"name":69,"tactic":149},{"name":71},{"id":151,"name":152,"tactic":153},"D3-NTF","Network Traffic Filtering",{"name":76},{"id":73,"name":74,"tactic":155},{"name":76},{"id":157,"name":158,"techniques":159},"CAPEC-551","Modify Existing Service",[160],{"id":161,"name":162,"tactics":163,"countermeasures":170},"T1543","Create or Modify System Process",[164,167],{"id":165,"name":166},"TA0110","Persistence",{"id":168,"name":169},"TA0111","Privilege Escalation",[171,176,180,184,188,192,196,200,204,208,212,216,220,224,228],{"id":172,"name":173,"tactic":174},"D3-DI","Data Inventory",{"name":175},"Model",{"id":177,"name":178,"tactic":179},"D3-FA","File Analysis",{"name":39},{"id":181,"name":182,"tactic":183},"D3-FIM","File Integrity Monitoring",{"name":39},{"id":185,"name":186,"tactic":187},"D3-SFA","System File Analysis",{"name":39},{"id":189,"name":190,"tactic":191},"D3-FEV","File Eviction",{"name":44},{"id":193,"name":194,"tactic":195},"D3-DF","Decoy File",{"name":53},{"id":197,"name":198,"tactic":199},"D3-FE","File Encryption",{"name":58},{"id":201,"name":202,"tactic":203},"D3-SCP","System Configuration Permissions",{"name":58},{"id":205,"name":206,"tactic":207},"D3-RF","Restore File",{"name":71},{"id":209,"name":210,"tactic":211},"D3-RD","Restore Database",{"name":71},{"id":213,"name":214,"tactic":215},"D3-CF","Content Filtering",{"name":76},{"id":217,"name":218,"tactic":219},"D3-LFP","Local File Permissions",{"name":76},{"id":221,"name":222,"tactic":223},"D3-RFAM","Remote File Access Mediation",{"name":76},{"id":225,"name":226,"tactic":227},"D3-CQ","Content Quarantine",{"name":76},{"id":229,"name":230,"tactic":231},"D3-CM","Content Modification",{"name":76},{"id":233,"name":234,"techniques":235},"CAPEC-555","Remote Services with Stolen Credentials",[236,270,302],{"id":237,"name":238,"tactics":239,"countermeasures":243},"T1021","Remote Services",[240],{"id":241,"name":242},"TA0109","Lateral Movement",[244,246,248,250,252,254,256,258,260,264,268],{"id":91,"name":92,"tactic":245},{"name":39},{"id":95,"name":96,"tactic":247},{"name":39},{"id":99,"name":100,"tactic":249},{"name":39},{"id":103,"name":104,"tactic":251},{"name":39},{"id":107,"name":108,"tactic":253},{"name":39},{"id":111,"name":112,"tactic":255},{"name":39},{"id":115,"name":116,"tactic":257},{"name":39},{"id":119,"name":120,"tactic":259},{"name":39},{"id":261,"name":262,"tactic":263},"D3-CAA","Connection Attempt Analysis",{"name":39},{"id":265,"name":266,"tactic":267},"D3-ST","Session Termination",{"name":44},{"id":151,"name":152,"tactic":269},{"name":76},{"id":271,"name":272,"tactics":273,"countermeasures":277},"T1114.002","Remote Email Collection",[274],{"id":275,"name":276},"TA0100","Collection",[278,282,286,290,294,298],{"id":279,"name":280,"tactic":281},"D3-NNI","Network Node Inventory",{"name":175},{"id":283,"name":284,"tactic":285},"D3-PLM","Physical Link Mapping",{"name":175},{"id":287,"name":288,"tactic":289},"D3-LLM","Logical Link Mapping",{"name":175},{"id":291,"name":292,"tactic":293},"D3-EHB","Endpoint Health Beacon",{"name":39},{"id":295,"name":296,"tactic":297},"D3-ER","Email Removal",{"name":44},{"id":299,"name":300,"tactic":301},"D3-RNA","Restore Network Access",{"name":71},{"id":303,"name":304,"tactics":305,"countermeasures":310},"T1133","External Remote Services",[306,307],{"id":165,"name":166},{"id":308,"name":309},"TA0108","Initial Access",[311],{"id":265,"name":266,"tactic":312},{"name":44},{"id":314,"name":315,"techniques":316},"CAPEC-560","Use of Known Domain Credentials",[317],{"id":318,"name":319,"tactics":320,"countermeasures":330},"T1078","Valid Accounts",[321,324,327,328,329],{"id":322,"name":323},"TA0030","Defense Evasion",{"id":325,"name":326},"TA0005","Stealth",{"id":165,"name":166},{"id":168,"name":169},{"id":308,"name":309},[331,335,339,343,347,351,355,359,363],{"id":332,"name":333,"tactic":334},"D3-AM","Access Modeling",{"name":175},{"id":336,"name":337,"tactic":338},"D3-LAM","Local Account Monitoring",{"name":39},{"id":340,"name":341,"tactic":342},"D3-DAM","Domain Account Monitoring",{"name":39},{"id":344,"name":345,"tactic":346},"D3-AL","Account Locking",{"name":44},{"id":348,"name":349,"tactic":350},"D3-AA","Agent Authentication",{"name":58},{"id":352,"name":353,"tactic":354},"D3-CDP","Change Default Password",{"name":58},{"id":356,"name":357,"tactic":358},"D3-ULA","Unlock Account",{"name":71},{"id":360,"name":361,"tactic":362},"D3-RUAA","Restore User Account Access",{"name":71},{"id":364,"name":365,"tactic":366},"D3-UAP","User Account Permissions",{"name":76},{"id":368,"name":369,"techniques":370},"CAPEC-561","Windows Admin Shares with Stolen Credentials",[371],{"id":372,"name":373,"tactics":374,"countermeasures":376},"T1021.002","SMB/Windows Admin Shares",[375],{"id":241,"name":242},[377,379,381,383,385,387,389,391,393,395],{"id":91,"name":92,"tactic":378},{"name":39},{"id":95,"name":96,"tactic":380},{"name":39},{"id":99,"name":100,"tactic":382},{"name":39},{"id":103,"name":104,"tactic":384},{"name":39},{"id":107,"name":108,"tactic":386},{"name":39},{"id":111,"name":112,"tactic":388},{"name":39},{"id":115,"name":116,"tactic":390},{"name":39},{"id":119,"name":120,"tactic":392},{"name":39},{"id":261,"name":262,"tactic":394},{"name":39},{"id":151,"name":152,"tactic":396},{"name":76},{"id":398,"name":399,"techniques":400},"CAPEC-600","Credential Stuffing",[401],{"id":402,"name":399,"tactics":403,"countermeasures":405},"T1110.004",[404],{"id":32,"name":33},[406,410,414,416,418,420,422,424,426,428,430,432,436],{"id":407,"name":408,"tactic":409},"D3-AEM","Application Exception Monitoring",{"name":39},{"id":411,"name":412,"tactic":413},"D3-OPM","Operational Process Monitoring",{"name":39},{"id":91,"name":92,"tactic":415},{"name":39},{"id":95,"name":96,"tactic":417},{"name":39},{"id":99,"name":100,"tactic":419},{"name":39},{"id":103,"name":104,"tactic":421},{"name":39},{"id":107,"name":108,"tactic":423},{"name":39},{"id":111,"name":112,"tactic":425},{"name":39},{"id":115,"name":116,"tactic":427},{"name":39},{"id":119,"name":120,"tactic":429},{"name":39},{"id":261,"name":262,"tactic":431},{"name":39},{"id":433,"name":434,"tactic":435},"D3-ANAA","Administrative Network Activity Analysis",{"name":39},{"id":151,"name":152,"tactic":437},{"name":76},{"id":439,"name":440,"techniques":441},"CAPEC-644","Use of Captured Hashes (Pass The Hash)",[442],{"id":443,"name":444,"tactics":445,"countermeasures":448},"T1550.002","Pass the Hash",[446,447],{"id":322,"name":323},{"id":241,"name":242},[449,453,457,461,465,469,473,477,481,485,489,493],{"id":450,"name":451,"tactic":452},"D3-PLA","Process Lineage Analysis",{"name":39},{"id":454,"name":455,"tactic":456},"D3-PSMD","Process Self-Modification Detection",{"name":39},{"id":458,"name":459,"tactic":460},"D3-PSA","Process Spawn Analysis",{"name":39},{"id":462,"name":463,"tactic":464},"D3-PT","Process Termination",{"name":44},{"id":466,"name":467,"tactic":468},"D3-PS","Process Suspension",{"name":44},{"id":470,"name":471,"tactic":472},"D3-HR","Host Reboot",{"name":44},{"id":474,"name":475,"tactic":476},"D3-HS","Host Shutdown",{"name":44},{"id":478,"name":479,"tactic":480},"D3-KBPI","Kernel-based Process Isolation",{"name":76},{"id":482,"name":483,"tactic":484},"D3-SCF","System Call Filtering",{"name":76},{"id":486,"name":487,"tactic":488},"D3-HBPI","Hardware-based Process Isolation",{"name":76},{"id":490,"name":491,"tactic":492},"D3-ABPI","Application-based Process Isolation",{"name":76},{"id":494,"name":495,"tactic":496},"D3-WSAM","Web Session Access Mediation",{"name":76},{"id":498,"name":499,"techniques":500},"CAPEC-645","Use of Captured Tickets (Pass The Ticket)",[501],{"id":502,"name":503,"tactics":504,"countermeasures":507},"T1550.003","Pass the Ticket",[505,506],{"id":322,"name":323},{"id":241,"name":242},[508,510,512,514,516,518,520,522,524,526,528,530],{"id":450,"name":451,"tactic":509},{"name":39},{"id":454,"name":455,"tactic":511},{"name":39},{"id":458,"name":459,"tactic":513},{"name":39},{"id":462,"name":463,"tactic":515},{"name":44},{"id":466,"name":467,"tactic":517},{"name":44},{"id":470,"name":471,"tactic":519},{"name":44},{"id":474,"name":475,"tactic":521},{"name":44},{"id":478,"name":479,"tactic":523},{"name":76},{"id":482,"name":483,"tactic":525},{"name":76},{"id":486,"name":487,"tactic":527},{"name":76},{"id":490,"name":491,"tactic":529},{"name":76},{"id":494,"name":495,"tactic":531},{"name":76},{"id":533,"name":534,"techniques":535},"CAPEC-652","Use of Known Kerberos Credentials",[536],{"id":537,"name":538,"tactics":539,"countermeasures":541},"T1558","Steal or Forge Kerberos Tickets",[540],{"id":32,"name":33},[542,544,546,548,550,552,554,556,558,560,562,564,566,568,570,572,574,576,578,580,582],{"id":91,"name":92,"tactic":543},{"name":39},{"id":95,"name":96,"tactic":545},{"name":39},{"id":99,"name":100,"tactic":547},{"name":39},{"id":103,"name":104,"tactic":549},{"name":39},{"id":107,"name":108,"tactic":551},{"name":39},{"id":111,"name":112,"tactic":553},{"name":39},{"id":115,"name":116,"tactic":555},{"name":39},{"id":119,"name":120,"tactic":557},{"name":39},{"id":36,"name":37,"tactic":559},{"name":39},{"id":125,"name":126,"tactic":561},{"name":39},{"id":41,"name":42,"tactic":563},{"name":44},{"id":46,"name":47,"tactic":565},{"name":44},{"id":50,"name":51,"tactic":567},{"name":53},{"id":55,"name":56,"tactic":569},{"name":58},{"id":60,"name":61,"tactic":571},{"name":58},{"id":64,"name":65,"tactic":573},{"name":58},{"id":141,"name":142,"tactic":575},{"name":58},{"id":145,"name":146,"tactic":577},{"name":58},{"id":68,"name":69,"tactic":579},{"name":71},{"id":151,"name":152,"tactic":581},{"name":76},{"id":73,"name":74,"tactic":583},{"name":76},{"id":585,"name":586,"techniques":587},"CAPEC-653","Use of Known Operating System Credentials",[],[],[590],"GHSA-42f2-f9vc-6365",[],[593,595,597,599,601,603],{"_key":594},"RHSA-2020:2058",{"_key":596},"RHSA-2020:2059",{"_key":598},"RHSA-2020:2060",{"_key":600},"RHSA-2020:2511",{"_key":602},"RHSA-2020:2512",{"_key":604},"RHSA-2020:2513",[],[],"2020-01-16T17:42:14.000Z","2024-08-04T23:17:40.033Z","Modified",{"cisa_kev":611,"cisa_ransomware":611,"cisa_vendor":9,"epss_severity":612,"epss_score":613,"severity":614,"severity_score":615,"severity_version":616,"severity_source":617,"severity_vector":618,"severity_status":609},false,"low",0.01164,"high",7.5,"v3.1","nvd","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",[620,627,631,635,644,650,654,658,662,666,670,675,679,683,687,691,695],{"url":621,"sources":622,"tags":624},"https://lists.apache.org/thread.html/rd588ff96f18563aeb5f87ac8c6bce7aae86cb1a4d4be483f96e7208c%40%3Cannounce.apache.org%3E",[623,617],"cve.org",[625,626],"Mailing List","X Refsource MLIST",{"url":628,"sources":629,"tags":630},"https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3E",[623,617],[625,626],{"url":632,"sources":633,"tags":634},"https://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3E",[623,617],[625,626],{"url":636,"sources":637,"tags":639},"https://www.oracle.com/security-alerts/cpujul2020.html",[623,617,638],"osv_maven",[640,641,642,643],"X Refsource MISC","Patch","Third Party Advisory","WEB",{"url":645,"sources":646,"tags":647},"http://cxf.apache.org/security-advisories.data/CVE-2019-12423.txt.asc?version=1&modificationDate=1579178393000&api=v2",[623,617,638],[648,649,643],"X Refsource CONFIRM","Vendor Advisory",{"url":651,"sources":652,"tags":653},"https://www.oracle.com/security-alerts/cpuoct2020.html",[623,617,638],[640,641,642,643],{"url":655,"sources":656,"tags":657},"https://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3E",[623,617],[625,626],{"url":659,"sources":660,"tags":661},"https://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3E",[623,617],[625,626],{"url":663,"sources":664,"tags":665},"https://www.oracle.com/security-alerts/cpuApr2021.html",[623,617,638],[640,641,642,643],{"url":667,"sources":668,"tags":669},"https://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3E",[623,617],[625,626],{"url":671,"sources":672,"tags":673},"https://nvd.nist.gov/vuln/detail/CVE-2019-12423",[638],[674],"Advisory",{"url":676,"sources":677,"tags":678},"https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf@%3Ccommits.cxf.apache.org%3E",[638],[643],{"url":680,"sources":681,"tags":682},"https://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6@%3Ccommits.cxf.apache.org%3E",[638],[643],{"url":684,"sources":685,"tags":686},"https://lists.apache.org/thread.html/rd588ff96f18563aeb5f87ac8c6bce7aae86cb1a4d4be483f96e7208c@%3Cannounce.apache.org%3E",[638],[643],{"url":688,"sources":689,"tags":690},"https://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4@%3Ccommits.cxf.apache.org%3E",[638],[643],{"url":692,"sources":693,"tags":694},"https://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e@%3Ccommits.cxf.apache.org%3E",[638],[643],{"url":696,"sources":697,"tags":698},"https://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4@%3Ccommits.cxf.apache.org%3E",[638],[643],[],{"date":701,"score":613,"percentile":702},"2026-06-04",0.78962,[704,708,711,714,717,720,723,726,729,732,735,738,741,744,747,751,754,757,760,763,766,769,772,775,778,780,783,785,788,791,794,797,800,803,805,807,810,813,816,819,822,825,828,831,834,837,840,843,846,849,852,855,858,861,864,867,870,873,876,879,882,884,887,890,893,896,899,902,905,908,910,913,915,918,921,924,927,929,932,935,938,941,944,947,950,953,956,958,960,962],{"date":705,"score":706,"percentile":707},"2025-11-04",0.02256,0.8404,{"date":709,"score":706,"percentile":710},"2025-11-05",0.84045,{"date":712,"score":706,"percentile":713},"2025-11-06",0.84048,{"date":715,"score":706,"percentile":716},"2025-11-07",0.84053,{"date":718,"score":706,"percentile":719},"2025-11-08",0.84057,{"date":721,"score":706,"percentile":722},"2025-11-09",0.84051,{"date":724,"score":613,"percentile":725},"2025-11-10",0.77942,{"date":727,"score":613,"percentile":728},"2025-11-11",0.77944,{"date":730,"score":613,"percentile":731},"2025-11-12",0.77961,{"date":733,"score":613,"percentile":734},"2025-11-13",0.77971,{"date":736,"score":613,"percentile":737},"2025-11-14",0.7798,{"date":739,"score":613,"percentile":740},"2025-11-15",0.77978,{"date":742,"score":613,"percentile":743},"2025-11-16",0.77979,{"date":745,"score":613,"percentile":746},"2025-11-17",0.77973,{"date":748,"score":749,"percentile":750},"2025-11-18",0.04393,0.87882,{"date":752,"score":749,"percentile":753},"2025-11-19",0.87886,{"date":755,"score":749,"percentile":756},"2025-11-20",0.8789,{"date":758,"score":613,"percentile":759},"2025-11-21",0.78,{"date":761,"score":613,"percentile":762},"2025-11-22",0.78001,{"date":764,"score":613,"percentile":765},"2025-11-23",0.77987,{"date":767,"score":613,"percentile":768},"2025-11-24",0.77985,{"date":770,"score":613,"percentile":771},"2025-11-25",0.77991,{"date":773,"score":613,"percentile":774},"2025-11-26",0.77996,{"date":776,"score":613,"percentile":777},"2025-11-27",0.77999,{"date":779,"score":613,"percentile":771},"2025-11-28",{"date":781,"score":613,"percentile":782},"2025-11-29",0.77998,{"date":784,"score":613,"percentile":774},"2025-11-30",{"date":786,"score":613,"percentile":787},"2025-12-01",0.78099,{"date":789,"score":613,"percentile":790},"2025-12-02",0.78108,{"date":792,"score":613,"percentile":793},"2025-12-03",0.78104,{"date":795,"score":613,"percentile":796},"2025-12-04",0.77995,{"date":798,"score":613,"percentile":799},"2025-12-05",0.78002,{"date":801,"score":613,"percentile":802},"2025-12-06",0.78005,{"date":804,"score":613,"percentile":777},"2025-12-07",{"date":806,"score":613,"percentile":799},"2025-12-08",{"date":808,"score":613,"percentile":809},"2025-12-09",0.78023,{"date":811,"score":613,"percentile":812},"2025-12-10",0.78047,{"date":814,"score":613,"percentile":815},"2025-12-11",0.78062,{"date":817,"score":613,"percentile":818},"2025-12-12",0.7808,{"date":820,"score":613,"percentile":821},"2025-12-13",0.78081,{"date":823,"score":613,"percentile":824},"2025-12-14",0.78078,{"date":826,"score":613,"percentile":827},"2025-12-15",0.78074,{"date":829,"score":613,"percentile":830},"2025-12-16",0.78086,{"date":832,"score":613,"percentile":833},"2025-12-17",0.78095,{"date":835,"score":613,"percentile":836},"2025-12-18",0.7811,{"date":838,"score":613,"percentile":839},"2025-12-19",0.78121,{"date":841,"score":613,"percentile":842},"2025-12-20",0.78115,{"date":844,"score":613,"percentile":845},"2025-12-21",0.78109,{"date":847,"score":613,"percentile":848},"2025-12-22",0.78111,{"date":850,"score":613,"percentile":851},"2025-12-23",0.78113,{"date":853,"score":613,"percentile":854},"2025-12-24",0.78125,{"date":856,"score":613,"percentile":857},"2025-12-25",0.78145,{"date":859,"score":613,"percentile":860},"2025-12-26",0.78142,{"date":862,"score":613,"percentile":863},"2025-12-27",0.78192,{"date":865,"score":613,"percentile":866},"2025-12-28",0.78131,{"date":868,"score":613,"percentile":869},"2025-12-29",0.78129,{"date":871,"score":613,"percentile":872},"2025-12-30",0.78135,{"date":874,"score":613,"percentile":875},"2025-12-31",0.78147,{"date":877,"score":613,"percentile":878},"2026-01-01",0.78262,{"date":880,"score":613,"percentile":881},"2026-01-02",0.78263,{"date":883,"score":613,"percentile":878},"2026-01-03",{"date":885,"score":613,"percentile":886},"2026-01-04",0.78149,{"date":888,"score":613,"percentile":889},"2026-01-05",0.78144,{"date":891,"score":613,"percentile":892},"2026-01-06",0.78154,{"date":894,"score":613,"percentile":895},"2026-01-07",0.78161,{"date":897,"score":613,"percentile":898},"2026-01-08",0.78169,{"date":900,"score":613,"percentile":901},"2026-01-09",0.78173,{"date":903,"score":613,"percentile":904},"2026-01-10",0.78175,{"date":906,"score":613,"percentile":907},"2026-01-11",0.78166,{"date":909,"score":613,"percentile":892},"2026-01-12",{"date":911,"score":613,"percentile":912},"2026-01-13",0.78152,{"date":914,"score":613,"percentile":901},"2026-01-14",{"date":916,"score":613,"percentile":917},"2026-01-15",0.78176,{"date":919,"score":613,"percentile":920},"2026-01-16",0.78183,{"date":922,"score":613,"percentile":923},"2026-01-17",0.7819,{"date":925,"score":613,"percentile":926},"2026-01-18",0.78185,{"date":928,"score":613,"percentile":920},"2026-01-19",{"date":930,"score":613,"percentile":931},"2026-01-20",0.78177,{"date":933,"score":613,"percentile":934},"2026-01-21",0.78181,{"date":936,"score":613,"percentile":937},"2026-01-22",0.78189,{"date":939,"score":613,"percentile":940},"2026-01-23",0.78216,{"date":942,"score":613,"percentile":943},"2026-01-24",0.78227,{"date":945,"score":613,"percentile":946},"2026-01-25",0.78222,{"date":948,"score":613,"percentile":949},"2026-01-26",0.78215,{"date":951,"score":613,"percentile":952},"2026-01-27",0.78213,{"date":954,"score":613,"percentile":955},"2026-01-28",0.78218,{"date":957,"score":613,"percentile":952},"2026-01-29",{"date":959,"score":613,"percentile":940},"2026-01-30",{"date":961,"score":613,"percentile":955},"2026-01-31",{"date":963,"score":613,"percentile":964},"2026-02-01",0.78325,[966,976],{"source":617,"cvss_v2_0":967,"cvss_v3_0":9,"cvss_v3_1":972,"cvss_v4_0":9},{"baseScore":968,"baseSeverity":9,"vectorString":969,"impactScore":970,"exploitabilityScore":971},4.3,"AV:N/AC:M/Au:N/C:P/I:N/A:N",2.9,8.6,{"baseScore":615,"baseSeverity":973,"vectorString":618,"impactScore":974,"exploitabilityScore":975},"HIGH",6,10,{"source":638,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":977,"cvss_v4_0":9},{"baseScore":615,"baseSeverity":9,"vectorString":618,"impactScore":974,"exploitabilityScore":975},[979,997,1009,1014,1021,1029,1036,1041,1050,1058],{"ecosystem":9,"name":980,"vendor":981,"product":980,"cpe_part":982,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":983},"cxf","apache","a",[984,990,995],{"version":985,"is_range":986,"range_type":987,"version_start":9,"version_start_type":9,"version_end":988,"version_end_type":989,"fixed_in":9},"lt3.2.12",true,"cpe","3.2.12","excluding",{"version":991,"is_range":986,"range_type":987,"version_start":992,"version_start_type":993,"version_end":994,"version_end_type":989,"fixed_in":9},"gte3.3.0_lt3.3.5","3.3.0","including","3.3.5",{"version":996,"is_range":611,"range_type":623,"version_start":996,"version_start_type":993,"version_end":996,"version_end_type":993,"fixed_in":9},"All versions of Apache CXF prior to 3.3.5 and 3.2.12.",{"ecosystem":998,"name":999,"vendor":1000,"product":1001,"cpe_part":9,"purl_type":1002,"purl_namespace":1000,"purl_name":1001,"source":9,"versions":1003},"Maven","org.apache.cxf:apache-cxf","org.apache.cxf","apache-cxf","maven",[1004,1007],{"version":1005,"is_range":986,"range_type":1006,"version_start":9,"version_start_type":9,"version_end":988,"version_end_type":989,"fixed_in":9},"lt3_2_12","ecosystem",{"version":1008,"is_range":986,"range_type":1006,"version_start":992,"version_start_type":993,"version_end":994,"version_end_type":989,"fixed_in":9},"gte3_3_0_lt3_3_5",{"ecosystem":998,"name":1010,"vendor":1000,"product":980,"cpe_part":9,"purl_type":1002,"purl_namespace":1000,"purl_name":980,"source":9,"versions":1011},"org.apache.cxf:cxf",[1012,1013],{"version":1005,"is_range":986,"range_type":1006,"version_start":9,"version_start_type":9,"version_end":988,"version_end_type":989,"fixed_in":9},{"version":1008,"is_range":986,"range_type":1006,"version_start":992,"version_start_type":993,"version_end":994,"version_end_type":989,"fixed_in":9},{"ecosystem":9,"name":1015,"vendor":1016,"product":1017,"cpe_part":982,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":1018},"commerce guided search","oracle","commerce_guided_search",[1019],{"version":1020,"is_range":611,"range_type":987,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.3.2",{"ecosystem":9,"name":1022,"vendor":1016,"product":1023,"cpe_part":982,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":1024},"communications diameter signaling router","communications_diameter_signaling_router",[1025],{"version":1026,"is_range":986,"range_type":987,"version_start":1027,"version_start_type":993,"version_end":1028,"version_end_type":993,"fixed_in":9},"gte8.0.0_lte8.2.2","8.0.0","8.2.2",{"ecosystem":9,"name":1030,"vendor":1016,"product":1031,"cpe_part":982,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":1032},"communications element manager","communications_element_manager",[1033],{"version":1034,"is_range":986,"range_type":987,"version_start":1035,"version_start_type":993,"version_end":1028,"version_end_type":993,"fixed_in":9},"gte8.2.0_lte8.2.2","8.2.0",{"ecosystem":9,"name":1037,"vendor":1016,"product":1038,"cpe_part":982,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":1039},"communications session report manager","communications_session_report_manager",[1040],{"version":1034,"is_range":986,"range_type":987,"version_start":1035,"version_start_type":993,"version_end":1028,"version_end_type":993,"fixed_in":9},{"ecosystem":9,"name":1042,"vendor":1016,"product":1043,"cpe_part":982,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":1044},"communications session route manager","communications_session_route_manager",[1045,1047,1048],{"version":1046,"is_range":611,"range_type":987,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"8.1.1",{"version":1035,"is_range":611,"range_type":987,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},{"version":1049,"is_range":611,"range_type":987,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"8.2.1",{"ecosystem":9,"name":1051,"vendor":1016,"product":1052,"cpe_part":982,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":1053},"flexcube private banking","flexcube_private_banking",[1054,1056],{"version":1055,"is_range":611,"range_type":987,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"12.0.0",{"version":1057,"is_range":611,"range_type":987,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"12.1.0",{"ecosystem":9,"name":1059,"vendor":1016,"product":1060,"cpe_part":982,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":1061},"retail order broker","retail_order_broker",[1062],{"version":1063,"is_range":611,"range_type":987,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"15.0"]