Description
Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0979 | Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX. |
Github GHSA |
GHSA-ffm7-7r8g-77xm | Apache CXF JMX Integration is vulnerable to a MITM attack |
References
History
No history.
Subscriptions
Apache
Subscribe
Cxf
Subscribe
Netapp
Subscribe
Oncommand Workflow Automation
Subscribe
Snapmanager
Subscribe
Oracle
Subscribe
Communications Diameter Signaling Router
Subscribe
Communications Diameter Signaling Router Idih\
Subscribe
Communications Element Manager
Subscribe
Communications Session Report Manager
Subscribe
Communications Session Route Manager
Subscribe
Enterprise Manager Base Platform
Subscribe
Peoplesoft Enterprise Peopletools
Subscribe
Redhat
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Enterprise Application Platform Cd
Subscribe
Jboss Enterprise Bpms Platform
Subscribe
Jboss Enterprise Brms Platform
Subscribe
Jboss Single Sign On
Subscribe
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T06:54:00.267Z
Reserved: 2019-12-02T00:00:00.000Z
Link: CVE-2020-1954
No data.
Status : Modified
Published: 2020-04-01T21:15:14.597
Modified: 2024-11-21T05:11:43.723
Link: CVE-2020-1954
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA