PT-2017-6822 · Apache · Apache Cxf Fediz
Colm O Heigeartaigh
·
Published
2017-06-07
·
Updated
2021-06-16
·
CVE-2015-5175
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apache CXF Fediz versions 1.1.0 through 1.1.3
Apache CXF Fediz versions 1.2.x prior to 1.2.1
Description
The issue allows remote attackers to cause a denial of service. This can be achieved through application plugins in Apache CXF Fediz.
Recommendations
For Apache CXF Fediz versions 1.1.0 through 1.1.2, update to version 1.1.3 to resolve the issue.
For Apache CXF Fediz versions 1.2.x prior to 1.2.1, update to version 1.2.1 to resolve the issue.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Cxf Fediz