CVE-2020-13954
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all versions of Apache CXF prior to 3.4.1 and 3.3.8. Please note that this is a separate issue to CVE-2019-17573.
Published:Nov 12, 2020
Last Modified:Feb 13, 2025
EPS:Nov 12, 2020
EPSS Score:0.08034
CVSS Score:6.1
Affected Products
Vendor
Product
Action
Vendor
Apache
Product
Cxf
Apache
Cxf
Vendor
Netapp
Product
Snap Creator Framework
Netapp
Snap Creator Framework
Vendor
Netapp
Product
Vasa Provider For Clustered Data Ontap
Netapp
Vasa Provider For Clustered Data Ontap
Vendor
Oracle
Product
Business Intelligence
Oracle
Business Intelligence
Vendor
Oracle
Product
Communications Messaging Server
Oracle
Communications Messaging Server
Vendor
Oracle
Product
Retail Order Broker Cloud Service
Oracle
Retail Order Broker Cloud Service
Vendor
Redhat
Product
Integration
Redhat
Integration
Vendor
Redhat
Product
Jboss Fuse
Redhat
Jboss Fuse
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
