Apache CXF
cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*
- >= 4.2.0, < 4.2.1
- >= 4.0.0, < 4.1.6
- < 3.6.11
A vulnerability exists in the WS-Transfer module of Apache CXF due to an insecure XML parser configuration, which may allow attackers to conduct XML External Entity (XXE) attacks. This issue affects Apache CXF versions 4.2.0 prior to 4.2.1, 4.0.0 prior to 4.1.6, and versions prior to 3.6.11.
Exploitation of this vulnerability could lead to XXE attacks, allowing attackers to interfere with the application’s processing of XML, potentially accessing internal files or services.
Users are advised to upgrade to Apache CXF versions 4.2.1, 4.1.6, or 3.6.11, all of which address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.