SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-17573

This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into the web page.

MEDIUM 6.1EPSS 7.05%

Does this matter?

Lower severity and a low EPSS score (7.05%). Track it; it rarely justifies an emergency change on its own.

Description

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into the web page. Please note that the attack exploits a feature which is not typically not present in modern browsers, who remove dot segments before sending the request. However, Mobile applications may be vulnerable.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
7.05% probability · 94th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
apache/cxf · oracle/commerce guided search · oracle/communications element manager · oracle/communications session report manager · oracle/communications session route manager · oracle/flexcube private banking · oracle/retail order broker
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.