CVE-2017-12624

Related Vulnerabilities: CVE-2017-12624  

Apache CXF supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications. It is possible to craft a message attachment header that could lead to a Denial of Service (DoS) attack on a CXF web service provider. Both JAX-WS and JAX-RS services are vulnerable to this attack. From Apache CXF 3.2.1 and 3.1.14, message attachment headers that are greater than 300 characters will be rejected by default. This value is configurable via the property "attachment-max-header-size".

The MITRE CVE dictionary describes this issue as:

Apache CXF supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications. It is possible to craft a message attachment header that could lead to a Denial of Service (DoS) attack on a CXF web service provider. Both JAX-WS and JAX-RS services are vulnerable to this attack. From Apache CXF 3.2.1 and 3.1.14, message attachment headers that are greater than 300 characters will be rejected by default. This value is configurable via the property "attachment-max-header-size".

Find out more about CVE-2017-12624 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

CVSS3 Base Score 5.3
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity Impact None
Availability Impact Low

Red Hat Security Errata

Platform Errata Release Date
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server RHSA-2018:2423 2018-08-15
Red Hat Single Sign-On 7.2 RHSA-2018:2428 2018-08-15
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server RHSA-2018:2424 2018-08-15
Red Hat JBoss EAP 7.1 RHSA-2018:2425 2018-08-15

Affected Packages State

Platform Package State
Red Hat Single Sign-On 7 cxf Not affected
Red Hat JBoss Portal Platform 6 cxf Not affected
Red Hat JBoss Operations Network 3 cxf Not affected
Red Hat JBoss Fuse Service Works 6 cxf Will not fix
Red Hat JBoss Fuse 7 cxf Will not fix
Red Hat JBoss Fuse 6 cxf Will not fix
Red Hat JBoss Enterprise SOA Platform 5 cxf Will not fix
Red Hat JBoss EAP 6 cxf Will not fix
Red Hat JBoss EAP 5 cxf Will not fix
Red Hat JBoss Data Virtualization 6 cxf Not affected
Red Hat JBoss Data Grid 6 cxf Not affected
Red Hat JBoss BRMS 6 cxf Not affected
Red Hat JBoss BRMS 5 cxf Not affected
Red Hat JBoss BPMS 6 cxf Not affected