Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2012-5633

The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.

CVSS v2:

  • Severity: Medium
  • Score: 5.8
  • AV:N/AC:M/Au:N/C:P/I:P/A:N
Software From Fixed in
apache / cxf 2.5.2 2.5.2.x
apache / cxf 2.5.3 2.5.3.x
apache / cxf 2.5.0 2.5.0.x
apache / cxf 2.5.1 2.5.1.x
apache / cxf 2.5.5 2.5.5.x
apache / cxf 2.5.6 2.5.6.x
apache / cxf - 2.5.7.x
apache / cxf 2.5.4 2.5.4.x
apache / cxf 2.6.0 2.6.0.x
apache / cxf 2.6.2 2.6.2.x
apache / cxf 2.6.3 2.6.3.x
apache / cxf 2.6.4 2.6.4.x
apache / cxf 2.6.1 2.6.1.x
apache / cxf 2.7.0 2.7.0.x
apache / cxf 2.7.1 2.7.1.x
org.apache.cxf / cxf - 2.5.8
org.apache.cxf / cxf 2.6.0 2.6.5
org.apache.cxf / cxf 2.7.0 2.7.2