CVE-2019-17573
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into the web page. Please note that the attack exploits a feature which is not typically not present in modern browsers, who remove dot segments before sending the request.
However, Mobile applications may be vulnerable.
MEDIUM · CVSS 6.1
EPSS 0.13981
Schedule remediation
- EPSS ≥ 0.10 - elevated exploitation probability
- EPSS percentile: top 6% of all CVEs by exploitation likelihood
Sigma rules0
YARA rules0