CVE-2014-0109

EUVD-2022-2671
Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (memory consumption) via a large request with the Content-Type set to text/html to a SOAP endpoint, which triggers an error.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 90%
Affected Products (NVD)
VendorProductVersion
apachecxf
2.7.0
apachecxf
2.7.1
apachecxf
2.7.2
apachecxf
2.7.3
apachecxf
2.7.4
apachecxf
2.7.5
apachecxf
2.7.6
apachecxf
2.7.7
apachecxf
2.7.8
apachecxf
2.7.9
apachecxf
2.7.10
apachecxf
𝑥
≤ 2.6.13
apachecxf
2.4.0
apachecxf
2.4.1
apachecxf
2.4.2
apachecxf
2.4.3
apachecxf
2.4.4
apachecxf
2.4.5
apachecxf
2.4.6
apachecxf
2.4.7
apachecxf
2.5.0
apachecxf
2.5.1
apachecxf
2.5.2
apachecxf
2.5.3
apachecxf
2.5.4
apachecxf
2.5.5
apachecxf
2.5.6
apachecxf
2.5.7
apachecxf
2.5.8
apachecxf
2.5.9
apachecxf
2.6.0
apachecxf
2.6.1
apachecxf
2.6.2
apachecxf
2.6.3
apachecxf
2.6.4
apachecxf
2.6.5
apachecxf
2.6.6
apachecxf
2.6.7
apachecxf
2.6.8
apachecxf
2.6.9
apachecxf
2.6.10
apachecxf
2.6.11
apachecxf
2.6.12
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References