CVE-2020-1954
Last modified
CVE-2020-1954 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. EPSS estimates a 6.15% chance of exploitation in the next 30 days.
Description
Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.
Metrics
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Cxf | < 3.2.13 |
| Apache | Cxf | >= 3.3.0, < 3.3.6 |
| Oracle | Communications Diameter Signaling Router | >= 8.0.0, <= 8.2.2 |
| Oracle | Communications Element Manager | >= 8.2.0, <= 8.2.2 |
| Oracle | Communications Session Report Manager | >= 8.2.0, <= 8.2.2 |
| Oracle | Enterprise Manager Base Platform | 13.2.1.0 |
| Oracle | Peoplesoft Enterprise Peopletools | 8.56 |
| Netapp | Oncommand Workflow Automation | All versions |
| Netapp | Snapmanager | All versions |
| Oracle | Communications Diameter Signaling Router Idih\ | >= 8.0.0, <= 8.2.2 |
| Oracle | Communications Session Route Manager | >= 8.2.0, <= 8.2.2 |
References
- https://security.netapp.com/advisory/ntap-20220210-0001/Patch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlPatch, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220210-0001/Patch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-1954?
How severe is CVE-2020-1954?
How do I fix CVE-2020-1954?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-19511Cross Site Scriptiong vulnerability in Typesetter 5.1 via th…6.1
- CVE-2020-19513Buffer overflow in FinalWire Ltd AIDA64 Engineer 6.00.5100 a…7.8
- CVE-2020-19515qdPM V9.1 is vulnerable to Cross Site Scripting (XSS) via qd…6.1
- CVE-2020-1952An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 t…9.8
- CVE-2020-19527iCMS 7.0.14 attackers to execute arbitrary OS commands via s…9.8
- CVE-2020-1953Apache Commons Configuration uses a third-party library to p…10
- CVE-2020-19547Directory Traversal vulnerability exists in PopojiCMS 2.0.1 …6.5
- CVE-2020-1955CouchDB version 3.0.0 shipped with a new configuration setti…9.8
- CVE-2020-19551Blacklist bypass issue exists in WUZHI CMS up to and includi…8.8
- CVE-2020-19553Cross Site Scripting (XSS) vlnerability exists in WUZHI CMS …5.4
- CVE-2020-19554Cross Site Scripting (XSS) vulnerability exists in ManageEng…6.1
- CVE-2020-19559An issue in Diebold Aglis XFS for Opteva v.4.1.61.1 allows a…9.8
Are you affected by CVE-2020-1954?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
