SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-12406

This leaves open the possibility of a denial of service type attack, where a malicious user crafts a message containing a very large number of message attachments.

MEDIUM 6.5EPSS 6.26%

Does this matter?

Lower severity and a low EPSS score (6.26%). Track it; it rarely justifies an emergency change on its own.

Description

Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility of a denial of service type attack, where a malicious user crafts a message containing a very large number of message attachments. From the 3.3.4 and 3.2.11 releases, a default limit of 50 message attachments is enforced. This is configurable via the message property "attachment-max-count".

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS
6.26% probability · 93th percentile
CISA KEV
Not listed
Weakness
CWE-770
Affected
apache/cxf · oracle/commerce guided search · oracle/flexcube private banking · oracle/retail order broker
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.