CVE-2020-1954
Last modified
CVE-2020-1954 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. EPSS estimates a 6.15% chance of exploitation in the next 30 days.
Description
Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.
Metrics
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Cxf | < 3.2.13 |
| Apache | Cxf | >= 3.3.0, < 3.3.6 |
| Oracle | Communications Diameter Signaling Router | >= 8.0.0, <= 8.2.2 |
| Oracle | Communications Element Manager | >= 8.2.0, <= 8.2.2 |
| Oracle | Communications Session Report Manager | >= 8.2.0, <= 8.2.2 |
| Oracle | Enterprise Manager Base Platform | 13.2.1.0 |
| Oracle | Peoplesoft Enterprise Peopletools | 8.56 |
| Netapp | Oncommand Workflow Automation | All versions |
| Netapp | Snapmanager | All versions |
| Oracle | Communications Diameter Signaling Router Idih\ | >= 8.0.0, <= 8.2.2 |
| Oracle | Communications Session Route Manager | >= 8.2.0, <= 8.2.2 |
References
- https://security.netapp.com/advisory/ntap-20220210-0001/Patch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlPatch, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220210-0001/Patch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-1954?
How severe is CVE-2020-1954?
How do I fix CVE-2020-1954?
Are you affected by CVE-2020-1954?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
