Apache CXF
cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*
- >= 4.2.0, < 4.2.1
- >= 4.0.0, < 4.1.6
- < 3.6.11
A vulnerability allowing LDAP injection has been identified in the LDAP Certificate repository of the XKMS server within Apache CXF. This vulnerability could enable an attacker to retrieve arbitrary certificates from the repository. It affects Apache CXF versions 4.2.0 prior to 4.2.1, 4.0.0 prior to 4.1.6, and versions prior to 3.6.11.
Exploitation of this vulnerability could lead to unauthorized retrieval of certificates from the LDAP repository.
Users are advised to upgrade to Apache CXF versions 4.2.1, 4.1.6, or 3.6.11, all of which address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.