Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-1954

Опубликовано: 01 апр. 2020
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6cxfOut of support scope
Red Hat BPM Suite 6cxf-coreOut of support scope
Red Hat Fuse 7cxf-coreAffected
Red Hat JBoss BRMS 6cxfOut of support scope
Red Hat JBoss BRMS 6cxf-coreOut of support scope
Red Hat JBoss Fuse 6cxf-coreOut of support scope
Red Hat OpenShift Application Runtimescxf-coreAffected
Red Hat support for Spring Bootcxf-coreAffected
EAP 7.3.3cxf-coreFixedRHSA-2020:424713.10.2020
EAP-CD 20 Tech Previewcxf-coreFixedRHSA-2020:358531.08.2020

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1824301cxf: JMX integration is vulnerable to a MITM attack

EPSS

Процентиль: 44%
0.00216
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
почти 6 лет назад

Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.

CVSS3: 5.3
github
почти 4 года назад

Apache CXF JMX Integration is vulnerable to a MITM attack

CVSS3: 5.3
fstec
почти 6 лет назад

Уязвимость каркаса для веб-сервисов Apache CXF, связанная с ошибками при установлении соединения, позволяющая нарушителю получить несанкционрованный доступ к защищаемой информации

EPSS

Процентиль: 44%
0.00216
Низкий

5.3 Medium

CVSS3