PT-2012-4724 · Apache · Apache Cxf

Published

2012-09-24

·

Updated

2023-02-13

·

CVE-2012-3451

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache CXF versions 2.4.0 through 2.4.9 Apache CXF versions 2.5.0 through 2.5.5 Apache CXF versions 2.6.0 through 2.6.2
Description The issue allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action String that is inconsistent with the message body.
Recommendations For Apache CXF versions 2.4.0 through 2.4.9, update to version 2.4.9 or later. For Apache CXF versions 2.5.0 through 2.5.5, update to version 2.5.5 or later. For Apache CXF versions 2.6.0 through 2.6.2, update to version 2.6.2 or later.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2012-3451
GHSA-55J7-F5WF-43M4
RHSA-2012:1591
RHSA-2012:1592
RHSA-2013:0257
RHSA-2013:0259

Affected Products

Apache Cxf