CVE-2014-3584

The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted SAML token in the authorization header of a request to a JAX-RS service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
VendorProductVersion
apachecxf
𝑥
≤ 2.6.10
apachecxf
2.6.1
apachecxf
2.7.0
apachecxf
2.7.1
apachecxf
2.7.2
apachecxf
2.7.3
apachecxf
2.7.4
apachecxf
2.7.5
apachecxf
2.7.6
apachecxf
2.7.7
apachecxf
3.0.0
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References