CVE-2019-17573
16.01.2020, 18:15
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into the web page. Please note that the attack exploits a feature which is not typically not present in modern browsers, who remove dot segments before sending the request. However, Mobile applications may be vulnerable.
Vendor | Product | Version |
---|---|---|
apache | cxf | 3.2.0 ≤ 𝑥 ≤ 3.2.12 |
apache | cxf | 3.3.0 ≤ 𝑥 < 3.3.5 |
oracle | commerce_guided_search | 11.3.2 |
oracle | communications_element_manager | 8.1.1 |
oracle | communications_element_manager | 8.2.0 |
oracle | communications_element_manager | 8.2.1 |
oracle | communications_session_report_manager | 8.1.1 |
oracle | communications_session_report_manager | 8.2.0 |
oracle | communications_session_report_manager | 8.2.1 |
oracle | communications_session_route_manager | 8.1.1 |
oracle | communications_session_route_manager | 8.2.0 |
oracle | communications_session_route_manager | 8.2.1 |
oracle | flexcube_private_banking | 12.0.0 |
oracle | flexcube_private_banking | 12.1.0 |
oracle | retail_order_broker | 15.0 |
𝑥
= Vulnerable software versions
References