Versio.io

CVE-2020-1954

Common vulnerabilities & exposures (CVE)

CVE databaseCVE database blogpostRelease & EoL database
 
Published at: - 01-04-2020 11:15
Last modified: - 21-02-2022 03:52
Total changes: - 7

Description

Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.

Common Vulnerability Scoring System (CVSS)

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
High
Attack complexity
Adjacent
Attack vector
None
Availability
High
Confidentiality
None
Integrity
None
Privileges required
Unchanged
Scope
None
User interaction
5.3
Base score
1.6
3.6
Exploitability score
Impact score
 

Verification logic

OR
OR
vendor=apache AND product=cxf AND versionEndExcluding=3.2.13
vendor=apache AND product=cxf AND versionStartIncluding=3.3.0 AND versionEndExcluding=3.3.6
OR
vendor=oracle AND product=communications_diameter_signaling_router AND versionEndIncluding=8.2.2 AND versionStartIncluding=8.0.0
vendor=oracle AND product=communications_element_manager AND versionEndIncluding=8.2.2 AND versionStartIncluding=8.2.0
vendor=oracle AND product=communications_session_report_manager AND versionEndIncluding=8.2.2 AND versionStartIncluding=8.2.0
vendor=oracle AND product=enterprise_manager_base_platform AND version=13.2.1.0
vendor=oracle AND product=peoplesoft_enterprise_peopletools AND version=8.56
OR
vendor=netapp AND product=oncommand_workflow_automation AND version=-
vendor=netapp AND product=snapmanager AND version=- AND target_software=sap
OR
vendor=oracle AND product= AND versionEndIncluding=8.2.2 AND versionStartIncluding=8.0.0
vendor=oracle AND product=communications_element_manager AND versionEndIncluding=8.2.2 AND versionStartIncluding=8.2.0
vendor=oracle AND product=communications_session_report_manager AND versionEndIncluding=8.2.2 AND versionStartIncluding=8.2.0
vendor=oracle AND product=communications_session_route_manager AND versionEndIncluding=8.2.2 AND versionStartIncluding=8.2.0
vendor=oracle AND product=enterprise_manager_base_platform AND version=13.2.1.0
vendor=oracle AND product=peoplesoft_enterprise_peopletools AND version=8.56
 

Reference

 


Keywords

NVD

 

CVE-2020-1954

 

CVE

 

Common vulnerabilities & exposures

 

CVSS

 

Common vulnerability scoring system

 

Security

 

Vulnerabilities

 

Exposures

 

We use cookies to ensure that we give you the best experience on our website. Read privacy policies for more information.