CVE-2012-5633

Severity
5.8MEDIUM
EPSS
1.8%
top 17.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 12
Latest updateMay 13

Description

The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.

CVSS vector

AV:N/AC:M/C:P/I:P/A:NExploitability: 8.6 | Impact: 4.9

Affected Packages2 packages

Mavenorg.apache.cxf:cxf2.6.02.6.5+2
NVDapache/cxf2.5.7+14

🔴Vulnerability Details

3
OSV
Improper Authentication in Apache CXF2022-05-13
GHSA
Improper Authentication in Apache CXF2022-05-13
CVEList
CVE-2012-5633: The URIMappingInterceptor in Apache CXF before 22013-03-12

📋Vendor Advisories

1
Red Hat
apache-cxf: Bypass of security constraints on WS endpoints when using WSS4JInInterceptor2013-02-08

💬Community

3
Bugzilla
CVE-2012-5633 CVE-2013-0239 cxf various flaws [fedora-all]2013-02-08
Bugzilla
CVE-2012-5633 CVE-2013-0239 jbossws-cxf various flaws [fedora-all]2013-02-08
Bugzilla
CVE-2012-5633 jbossws-cxf, apache-cxf: Bypass of security constraints on WS endpoints when using WSS4JInInterceptor2012-12-20
CVE-2012-5633 (MEDIUM CVSS 5.8) | The URIMappingInterceptor in Apache | cvebase.io