CVE-2018-8039 — Improper Handling of Exceptional Conditions in Apache CXF
Severity
8.1HIGHNVD
EPSS
2.9%
top 13.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 2
Latest updateApr 15
Description
It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.handler.pkgs", "com.sun.net.ssl.internal.www.protocol");'. When this system property is set, CXF uses some reflection to try to make the HostnameVerifier work with the old com.sun.net.ssl.HostnameVerifier interface. However, the default HostnameVerifier implementation in CXF does not implement the method in this interface, and an exception is thrown. However, in Apache CXF prio…
CVSS vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9
Affected Packages3 packages
Patches
🔴Vulnerability Details
3📋Vendor Advisories
3Oracle
▶
Oracle▶
Oracle Oracle Retail Applications Risk Matrix: System Administration (Apache CXF) — CVE-2018-8039↗2020-01-15
Red Hat
▶