CVE-2020-13954

CVSS v3.1 6.1 (Medium)
61% Progress
CVSS v2.0 4.3 (Medium)
43% Progress
EPSS 19.04 % (96th)
19.04% Progress
Affected Products 6
Advisories 1

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all versions of Apache CXF prior to 3.4.1 and 3.3.8. Please note that this is a separate issue to CVE-2019-17573.

Weaknesses
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Related CVEs
CVE Status
PUBLISHED
CNA
Apache Software Foundation
Published Date
2020-11-12 13:15:11
(3 years ago)
Updated Date
2023-11-07 03:17:03
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Apache Cxf prior 3.3.8 version cpe:2.3:a:apache:cxf < 3.3.8
  Apache Cxf from 3.4.0 version and prior 3.4.1 version cpe:2.3:a:apache:cxf >= 3.4.0 < 3.4.1

Configuration #2

    CPE23 From Up To
  Netapp Snap Creator Framework cpe:2.3:a:netapp:snap_creator_framework:-
  Netapp Vasa Provider for Clustered Data Ontap from 9.6 version cpe:2.3:a:netapp:vasa_provider_for_clustered_data_ontap >= 9.6

Configuration #3

    CPE23 From Up To
  Oracle Business Intelligence 5.5.0.0.0 cpe:2.3:a:oracle:business_intelligence:5.5.0.0.0:*:*:*:enterprise
  Oracle Business Intelligence 5.9.0.0.0 cpe:2.3:a:oracle:business_intelligence:5.9.0.0.0:*:*:*:enterprise
  Oracle Business Intelligence 12.2.1.3.0 cpe:2.3:a:oracle:business_intelligence:12.2.1.3.0:*:*:*:enterprise
  Oracle Business Intelligence 12.2.1.4.0 cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise
  Oracle Retail Order Broker Cloud Service 15.0 cpe:2.3:a:oracle:retail_order_broker_cloud_service:15.0
  Oracle Communications Messaging Server 8.0.2 cpe:2.3:o:oracle:communications_messaging_server:8.0.2
  Oracle Communications Messaging Server 8.1 cpe:2.3:o:oracle:communications_messaging_server:8.1
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...