CVE-2012-3451
published 2012-09-24CVE-2012-3451: Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header…
PriorityP431medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
8.88%
94.7th percentile
Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action String that is inconsistent with the message body.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | < 2.4.9 | 2.4.9 |
| apache | cxf | >= 2.5.0 < 2.5.5 | 2.5.5 |
| apache | cxf | >= 2.6.0 < 2.6.2 | 2.6.2 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
apache-cxf: SOAPAction spoofing on document literal web services
vendor_redhat·2012-09-19·CVSS 4.3
CVE-2012-3451 [MEDIUM] apache-cxf: SOAPAction spoofing on document literal web services
apache-cxf: SOAPAction spoofing on document literal web services
Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action String that is inconsistent with the message body.
Package: Security (Red Hat JBoss BRMS 5) - Affected
Package: Security (Red Hat JBoss SOA Platform 5) - Affected
OSV
Remote web-service operation execution in Apache CXF
osv·2022-05-13
CVE-2012-3451 [HIGH] Remote web-service operation execution in Apache CXF
Remote web-service operation execution in Apache CXF
Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action String that is inconsistent with the message body.
GHSA
Remote web-service operation execution in Apache CXF
ghsa·2022-05-13
CVE-2012-3451 [HIGH] CWE-20 Remote web-service operation execution in Apache CXF
Remote web-service operation execution in Apache CXF
Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action String that is inconsistent with the message body.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3451 jbossws-cxf, apache-cxf: SOAPAction spoofing on document literal web services [fedora-17]
bugzilla·2012-09-19·CVSS 4.3
CVE-2012-3451 [MEDIUM] CVE-2012-3451 jbossws-cxf, apache-cxf: SOAPAction spoofing on document literal web services [fedora-17]
CVE-2012-3451 jbossws-cxf, apache-cxf: SOAPAction spoofing on document literal web services [fedora-17]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org
Bugzilla
CVE-2012-3451 jbossws-cxf, apache-cxf: SOAPAction spoofing on document literal web services
bugzilla·2012-08-27·CVSS 4.3
CVE-2012-3451 [MEDIUM] CVE-2012-3451 jbossws-cxf, apache-cxf: SOAPAction spoofing on document literal web services
CVE-2012-3451 jbossws-cxf, apache-cxf: SOAPAction spoofing on document literal web services
Apache CXF is vulnerable to SOAPAction spoofing attacks under certain conditions. If web services are exposed via Apache CXF that use a unique SOAPAction for each service operation, then a remote attacker could perform SOAPAction spoofing to call a forbidden operation if it accepts the same parameters as an allowed operation. WS-Policy validation is performed against the operation being invoked, and an attack must pass validation to be successful.
Discussion:
This is now public via upstream advisory:
[1] http://cxf.apache.org/cve-2012-3451.html
Relevant upstream patch:
[2] http://svn.apache.org/viewvc?view=revision&revision=1368559
---
This issue affects the version of the jbossws-cxf package,
http://cxf.apache.org/cve-2012-3451.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1591.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1592.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1594.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0256.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0257.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0258.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0259.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0726.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0743.htmlhttp://secunia.com/advisories/51607http://secunia.com/advisories/52183http://svn.apache.org/viewvc?view=revision&revision=1368559https://bugzilla.redhat.com/show_bug.cgi?id=851896https://exchange.xforce.ibmcloud.com/vulnerabilities/78734https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3Ehttp://cxf.apache.org/cve-2012-3451.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1591.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1592.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1594.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0256.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0257.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0258.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0259.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0726.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0743.htmlhttp://secunia.com/advisories/51607http://secunia.com/advisories/52183http://svn.apache.org/viewvc?view=revision&revision=1368559https://bugzilla.redhat.com/show_bug.cgi?id=851896https://exchange.xforce.ibmcloud.com/vulnerabilities/78734https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3E
2012-09-24
Published