CVE Database
/

CVE-2020-1954

Back to search

CVE-2020-1954

Published: Apr 1, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.

VendorProductVersions

Apache

Apache CXF

affected
affects all versions prior to 3.3.6 and 3.2.13

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now