CyberSec.Space Logo
CVEブラウザに戻る

CVE-2019-12419

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0800%
EPSS Percentile1.26th
Published2019年11月6日
Last Modified2024年11月21日

Vulnerability Description

Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to somehow steal an authorization code issued to another client, then they could exploit this vulnerability to obtain an access token for the other client.

Affected Platforms (CPE)

📦
Apache

Cxf

>= 3.2.0 and < 3.2.11
📦
Apache

Cxf

>= 3.3.0 and < 3.3.4
📦
Oracle

Commerce Guided Search

= 11.3.2
📦
Oracle

Enterprise Manager Base Platform

= 13.2.1.0
📦
Oracle

Flexcube Private Banking

= 12.0.0
📦
Oracle

Flexcube Private Banking

= 12.1.0
📦
Oracle

Retail Order Broker

= 15.0

References & Advisories

関連する脆弱性情報