Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action String that is inconsistent with the message body.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache CXF SOAP 输入验证错误漏洞
Vulnerability Description
Apache CXF是美国阿帕奇(Apache)软件基金会的一个开源的Web服务框架。该框架支持多种Web服务标准、多种前端编程API等。 Apache CXF 2.4.9之前版本、2.5.5之前的2.5.x版本、2.6.2之前的2.6.x版本中存在输入验证错误漏洞,该漏洞源于报头含有SOAP Action字符串的SOAP请求的主干数据没有充分验证。远程攻击者可执行非预期的网络服务操作。
CVSS Information
N/A
Vulnerability Type
N/A