CVE-2019-17573

Aliases:GHSA-f93p-f762-vr53
Modified
Published: 16 Jan 2020, 17:50
Last modified:05 Aug 2024, 01:47

Vulnerability Summary

Overall Risk (default)
medium
27/100
CVSS Score
6.1 MEDIUM
v3.1 (nvd)
EPSS Score
13.98% MEDIUM
14% probability -2.14%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

16 Jan 2020, 17:50
Published
Vulnerability first disclosed
05 Aug 2024, 01:47
Last Modified
Vulnerability information updated

Description

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into the web page. Please note that the attack exploits a feature which is not typically not present in modern browsers, who remove dot segments before sending the request. However, Mobile applications may be vulnerable.

CVSS Metrics

  • v3.1MEDIUMScore: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS Trends

Current EPSS score: 13.98% Percentile: 94%

Techniques & Countermeasures

  • CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Affected Systems

  • apachecxf

    ≥ 3.2.0, ≤ 3.2.12 | ≥ 3.3.0, < 3.3.5 | All versions of Apache CXF prior to 3.3.5 and 3.2.12.

  • org.apache.cxfapache-cxf

    < 3.2.12 | ≥ 3.3.0, < 3.3.5

  • org.apache.cxfcxf

    < 3.2.12 | ≥ 3.3.0, < 3.3.5

  • oraclecommerce_guided_search

    11.3.2

  • oraclecommunications_element_manager

    8.1.1 | 8.2.0 | 8.2.1

  • oraclecommunications_session_report_manager

    8.1.1 | 8.2.0 | 8.2.1

  • oraclecommunications_session_route_manager

    8.1.1 | 8.2.0 | 8.2.1

  • oracleflexcube_private_banking

    12.0.0 | 12.1.0

  • oracleretail_order_broker

    15.0

References (26)