CVE-2019-17573: Apache Cxf
Medium severity, CVSS 6.1. EPSS: 7.1% chance of exploitation in the next 30 days.
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into the web page. Please note that the attack exploits a feature which is not typically not present in modern browsers, who remove dot segments before sending the request. However, Mobile applications may be vulnerable.
Affected products
- Apache Cxf: from 3.2.0, up to and including 3.2.12; from 3.3.0, before 3.3.5 (fixed in 3.3.5)
- Oracle Commerce Guided Search: version 11.3.2 only
- Oracle Communications Element Manager: version 8.1.1 only; version 8.2.0 only; version 8.2.1 only
- Oracle Communications Session Report Manager: version 8.1.1 only; version 8.2.0 only; version 8.2.1 only
- Oracle Communications Session Route Manager: version 8.1.1 only; version 8.2.0 only; version 8.2.1 only
- Oracle Flexcube Private Banking: version 12.0.0 only; version 12.1.0 only
- Oracle Retail Order Broker: version 15.0 only
Published 2020-01-16. Last modified 2026-06-17.