4.3
CVSSv2

CVE-2014-0110

Published: 08/05/2014 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Apache CXF prior to 2.6.14 and 2.7.x prior to 2.7.11 allows remote malicious users to cause a denial of service (/tmp disk consumption) via a large invalid SOAP message.

Vulnerable Product Search on Vulmon Subscribe to Product

apache cxf 2.5.2

apache cxf 2.5.9

apache cxf 2.4.6

apache cxf 2.6.8

apache cxf 2.6.0

apache cxf 2.5.3

apache cxf 2.4.0

apache cxf 2.4.3

apache cxf 2.6.12

apache cxf 2.5.7

apache cxf 2.4.4

apache cxf 2.6.2

apache cxf 2.4.2

apache cxf 2.5.0

apache cxf 2.5.1

apache cxf 2.5.5

apache cxf 2.6.9

apache cxf 2.5.8

apache cxf 2.6.5

apache cxf 2.6.10

apache cxf 2.6.6

apache cxf 2.6.3

apache cxf 2.4.1

apache cxf 2.5.6

apache cxf 2.4.7

apache cxf 2.6.4

apache cxf 2.4.5

apache cxf 2.6.11

apache cxf 2.6.1

apache cxf

apache cxf 2.5.4

apache cxf 2.6.7

apache cxf 2.7.3

apache cxf 2.7.5

apache cxf 2.7.10

apache cxf 2.7.6

apache cxf 2.7.9

apache cxf 2.7.0

apache cxf 2.7.4

apache cxf 2.7.1

apache cxf 2.7.8

apache cxf 2.7.7

apache cxf 2.7.2

Vendor Advisories

It was found that when a large invalid SOAP message was processed by Apache CXF, it could be saved to a temporary file in the /tmp directory A remote attacker could send a specially crafted SOAP message that, when processed by an application using Apache CXF, would use an excessive amount of disk space, possibly causing a denial of service ...