← All CVEs

CVE-2017-5653

medium · 5.3

JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which allows remote attackers to spoof servers.

5.3
CVSS
11.2%
EPSS (exploit prob.)
96th
EPSS percentile
2017-04-18
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Weaknesses

CWE-295

Affected products

VendorProductAffected versions
apachecxf>= 3.0.0, <= 3.0.13
apachecxf>= 3.1.0, <= 3.1.11

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-5653