CVE-2018-8039Improper Handling of Exceptional Conditions in Apache CXF

Severity
8.1HIGHNVD
EPSS
2.9%
top 13.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 2
Latest updateApr 15

Description

It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.handler.pkgs", "com.sun.net.ssl.internal.www.protocol");'. When this system property is set, CXF uses some reflection to try to make the HostnameVerifier work with the old com.sun.net.ssl.HostnameVerifier interface. However, the default HostnameVerifier implementation in CXF does not implement the method in this interface, and an exception is thrown. However, in Apache CXF prio

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages3 packages

NVDapache/cxf3.2.03.2.5+1
CVEListV5apache_software_foundation/apache_cxf3.2.x prior to 3.2.5, prior to 3.1.16+1

Patches

🔴Vulnerability Details

3
GHSA
Apache CXF TLS hostname verification does not work correctly with com.sun.net.ssl.*2018-10-19
OSV
Apache CXF TLS hostname verification does not work correctly with com.sun.net.ssl.*2018-10-19
CVEList
CVE-2018-8039: It is possible to configure Apache CXF to use the com2018-07-02

📋Vendor Advisories

3
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Apache CXF) — CVE-2018-80392020-04-15
Oracle
Oracle Oracle Retail Applications Risk Matrix: System Administration (Apache CXF) — CVE-2018-80392020-01-15
Red Hat
apache-cxf: TLS hostname verification does not work correctly with com.sun.net.ssl.*2018-06-29

💬Community

2
Bugzilla
CVE-2018-8039 cxf: apache-cxf: TLS hostname verification does not work correctly with com.sun.net.ssl.* [fedora-all]2018-06-29
Bugzilla
CVE-2018-8039 apache-cxf: TLS hostname verification does not work correctly with com.sun.net.ssl.*2018-06-26
CVE-2018-8039 — Apache CXF vulnerability | cvebase