Description
The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5771 | The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request. |
Github GHSA |
GHSA-xf9f-32gh-h2w4 | Improper Authentication in Apache CXF |
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Subscriptions
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T21:14:16.218Z
Reserved: 2012-10-24T00:00:00.000Z
Link: CVE-2012-5633
No data.
Status : Deferred
Published: 2013-03-12T23:55:01.497
Modified: 2025-04-11T00:51:21.963
Link: CVE-2012-5633
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA