CVE-2017-12624

medium
Published 2017-11-14 · Modified 2024-02-16
CVSS v3
5.5
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
VIR risk
5.5

Description

Improper Input Validation in Apache CXF

Predictions

Exploit likelihood
55%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.apache.cxf:cxf-core>=3.2.0,<3.2.13.2.1
java Mavenorg.apache.cxf:cxf-core>=3.1.0,<3.1.143.1.14
java Mavenorg.apache.cxf:cxf-core<3.0.163.0.16

Application impact

VendorProductVersionsFixed
apache apachecxf{"startIncluding":"3.0.0","endExcluding":"3.0.16"}3.0.16

References

💬 Discuss CVE-2017-12624 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.