Логотип exploitDog
bind:CVE-2020-1954
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-1954

Количество 4

Количество 4

redhat логотип

CVE-2020-1954

почти 6 лет назад

Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2020-1954

почти 6 лет назад

Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-ffm7-7r8g-77xm

почти 4 года назад

Apache CXF JMX Integration is vulnerable to a MITM attack

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2020-05180

почти 6 лет назад

Уязвимость каркаса для веб-сервисов Apache CXF, связанная с ошибками при установлении соединения, позволяющая нарушителю получить несанкционрованный доступ к защищаемой информации

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2020-1954

Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.

CVSS3: 5.3
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2020-1954

Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.

CVSS3: 5.3
0%
Низкий
почти 6 лет назад
github логотип
GHSA-ffm7-7r8g-77xm

Apache CXF JMX Integration is vulnerable to a MITM attack

CVSS3: 5.3
0%
Низкий
почти 4 года назад
fstec логотип
BDU:2020-05180

Уязвимость каркаса для веб-сервисов Apache CXF, связанная с ошибками при установлении соединения, позволяющая нарушителю получить несанкционрованный доступ к защищаемой информации

CVSS3: 5.3
0%
Низкий
почти 6 лет назад

Уязвимостей на страницу