7.8
CVSSv2

CVE-2016-8739

Published: 10/08/2017 Updated: 07/11/2023
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

The JAX-RS module in Apache CXF before 3.0.12 and 3.1.x before 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apache Abdera Parser which expands XML entities by default which represents a major XXE risk.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache cxf 3.1.4

apache cxf 3.1.3

apache cxf 3.1.1

apache cxf 3.1.2

apache cxf 3.1.6

apache cxf 3.1.0

apache cxf

apache cxf 3.1.5

apache cxf 3.1.7

apache cxf 3.1.8