SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-1954

If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack.

MEDIUM 5.3EPSS 6.15%

Does this matter?

Lower severity and a low EPSS score (6.15%). Track it; it rarely justifies an emergency change on its own.

Description

Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
6.15% probability · 93th percentile
CISA KEV
Not listed
Affected
apache/cxf · oracle/communications diameter signaling router · oracle/communications element manager · oracle/communications session report manager · oracle/enterprise manager base platform · oracle/peoplesoft enterprise peopletools · netapp/oncommand workflow automation · netapp/snapmanager · oracle/communications diameter signaling router idih\ · oracle/communications session route manager
Source
security@apache.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.