Apache CXF UsernameToken Information Disclosure Vulnerability
BID:68445
Info
Apache CXF UsernameToken Information Disclosure Vulnerability
| Bugtraq ID: | 68445 |
| Class: | Access Validation Error |
| CVE: |
CVE-2014-0035 |
| Remote: | Yes |
| Local: | No |
| Published: | May 01 2014 12:00AM |
| Updated: | May 12 2015 07:47PM |
| Credit: | Reported by the vendor |
| Vulnerable: |
Redhat JBoss Enterprise Application Platform 6.2.4 Redhat JBoss Enterprise Application Platform 6.2 EL6 Redhat JBoss Enterprise Application Platform 6.2 EL5 Redhat JBoss Enterprise Application Platform 6 EL6 Redhat JBoss Enterprise Application Platform 6 EL5 Redhat JBoss BRMS 6.0.3 Redhat Jboss Bpm Suite 6.0.3 Redhat Jboss Bpm Suite 6.0.1 Redhat Jboss Bpm Suite 6.0.0 Apache Apache CXF 2.7.9 Apache Apache CXF 2.7.8 Apache Apache CXF 2.6.12 Apache Apache CXF 2.6.11 Apache Apache CXF 2.6.2 Apache Apache CXF 2.6.1 Apache Apache CXF 2.6 Apache Apache CXF 2.7.4 Apache Apache CXF 2.7.3 Apache Apache CXF 2.7.2 Apache Apache CXF 2.6.7 Apache Apache CXF 2.6.6 Apache Apache CXF 2.6.5 |
| Not Vulnerable: |
Redhat JBoss BRMS 6.1 Redhat Jboss Bpm Suite 6.1 Apache Apache CXF 2.7.10 Apache Apache CXF 2.6.13 |
Discussion
Apache CXF UsernameToken Information Disclosure Vulnerability
Apache CXF is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may aid in launching further attacks.
The following versions are affected:
Apache CXF 2.6.x prior to 2.6.13
Apache CXF 2.7.x prior to 2.7.10
Apache CXF is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may aid in launching further attacks.
The following versions are affected:
Apache CXF 2.6.x prior to 2.6.13
Apache CXF 2.7.x prior to 2.7.10
Exploit / POC
Apache CXF UsernameToken Information Disclosure Vulnerability
Attackers can exploit this issue using a browser or readily available tools.
Attackers can exploit this issue using a browser or readily available tools.
Solution / Fix
Apache CXF UsernameToken Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Apache CXF UsernameToken Information Disclosure Vulnerability
References:
References:
- Apache CXF (Apache Software Foundation)