MEDIUM · 6.1

CVE-2019-17573

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which a...

Vulnerability Description

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into the web page. Please note that the attack exploits a feature which is not typically not present in modern browsers, who remove dot segments before sending the request. However, Mobile applications may be vulnerable.

CVSS Score

6.1

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
ApacheCxf>= 3.2.0, <= 3.2.12
OracleCommerce Guided Search11.3.2
OracleCommunications Element Manager8.1.1
OracleCommunications Session Report Manager8.1.1
OracleCommunications Session Route Manager8.1.1
OracleFlexcube Private Banking12.0.0
OracleRetail Order Broker15.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-17573?

CVE-2019-17573 is a vulnerability with a CVSS score of 6.1 (MEDIUM). By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which a...

How severe is CVE-2019-17573?

CVE-2019-17573 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-17573?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Cxf, Oracle Commerce Guided Search, Oracle Communications Element Manager, Oracle Communications Session Report Manager, Oracle Communications Session Route Manager.