XML Security Flaw in Apache CXF Affects Streaming Clients
CVE-2017-5653
5.3MEDIUM
Summary
The vulnerability in Apache CXF streaming clients prior to specified versions results from inadequate validation of service responses. Specifically, the clients do not ensure that the service response is properly signed or encrypted, making them susceptible to remote attackers who could exploit this flaw to impersonate legitimate servers. This can lead to unauthorized access and potential data breaches, impacting the integrity and confidentiality of communications.
Affected Version(s)
Apache CXF prior to 3.0.13
Apache CXF 3.1.x prior to 3.1.11
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved