Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache CXF 授权问题漏洞
Vulnerability Description
Apache CXF是美国阿帕奇(Apache)软件基金会的一个开源的Web服务框架。该框架支持多种Web服务标准、多种前端编程API等。 Apache CXF 2.5.8之前版本,2.6.5之前的2.6.x版本,2.7.2之前的2.7.x版本中的URIMappingInterceptor中存在授权问题漏洞,该漏洞源于使用WSS4JInInterceptor时,程序会绕过WS-Security处理。通过HTTP GET请求,远程攻击者利用该漏洞获得访问SOAP服务的权限。
CVSS Information
N/A
Vulnerability Type
N/A