Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2012-3451

Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action String that is inconsistent with the message body.

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:N/I:P/A:N

CWEs:

Software From Fixed in
apache / cxf - 2.4.9
apache / cxf 2.5.0 2.5.5
apache / cxf 2.6.0 2.6.2
org.apache.cxf / cxf - 2.4.9
org.apache.cxf / cxf 2.5.0 2.5.5
org.apache.cxf / cxf 2.6.0 2.6.2