6.1
CVSSv3

CVE-2020-13954

Published: 12/11/2020 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all versions of Apache CXF before 3.4.1 and 3.3.8. Please note that this is a separate issue to CVE-2019-17573.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache cxf

netapp snap creator framework -

netapp vasa provider for clustered data ontap

oracle retail order broker cloud service 15.0

oracle business intelligence 12.2.1.3.0

oracle business intelligence 12.2.1.4.0

oracle business intelligence 5.5.0.0.0

oracle communications messaging server 8.1

oracle communications messaging server 8.0.2

oracle business intelligence 5.9.0.0.0

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2020-13954: Apache CXF Reflected XSS in the services listing page via the styleSheetPath <!--X-Subject-Header-End--> <!--X ...

References