CVE-2020-13954: Apache Cxf

Medium severity, CVSS 6.1. EPSS: 40.9% chance of exploitation in the next 30 days.

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all versions of Apache CXF prior to 3.4.1 and 3.3.8. Please note that this is a separate issue to CVE-2019-17573.

Affected products

  • Apache Cxf: before 3.3.8 (fixed in 3.3.8); from 3.4.0, before 3.4.1 (fixed in 3.4.1)
  • Netapp Snap Creator Framework: affected versions not specified
  • Netapp Vasa Provider For Clustered Data Ontap: from 9.6
  • Oracle Business Intelligence: version 5.5.0.0.0 only; version 5.9.0.0.0 only; version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • Oracle Communications Messaging Server: version 8.0.2 only; version 8.1 only
  • Oracle Retail Order Broker Cloud Service: version 15.0 only

Published 2020-11-12. Last modified 2026-06-17.