vendor:
CXF
by:
Andreas Falkenberg, SEC Consult Vulnerability Lab; Christian Mainka, Ruhr-University Bochum; Juraj Somorovsky, Ruhr-University Bochum; Joerg Schwenk, Ruhr-University Bochum
9
CVSS
CRITICAL
Denial of Service
400
CWE
Product Name: CXF
Affected Version From: Apache CXF prior to 2.5.10, 2.6.7 and 2.7.4
Affected Version To: N/A
Patch Exists: YES
Related CWE: CVE-2013-2160
CPE: a:apache:cxf
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013
Denial of Service vulnerability
It is possible to execute Denial of Service attacks on Apache CXF, exploiting the fact that the streaming XML parser does not put limits on things like the number of elements, number of attributes, the nested structure of the document received, etc. The effects of these attacks can vary from causing high CPU usage, to causig the JVM to run out of memory.
Mitigation:
Immediately perform an update.