CVE-2019-12406

Description

Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility of a denial of service type attack, where a malicious user crafts a message containing a very large number of message attachments. From the 3.3.4 and 3.2.11 releases, a default limit of 50 message attachments is enforced. This is configurable via the message property "attachment-max-count".

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
4.134

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2019-12406 are fixed in Apache-apache-cxf 3.2.11Windows
Vulnerabilities CVE-2019-12406 are fixed in Apache-apache-cxf 3.3.4Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 10.5Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 10.6Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.4.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.4.1Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.1Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.2Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.4.2Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.3Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.4Windows
Vulnerabilities CVE-2019-12406,CVE-2019-12419 are fixed in Apache - cxf 3.2.11Windows
Vulnerabilities CVE-2019-12406,CVE-2019-12419 are fixed in Apache - cxf 3.3.4Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.1Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 19.0Windows
Multiple Vulnerabilities are affected in IBM Tivoli Application Dependency Discovery Manager 7.3.0Windows
Vulnerabilities CVE-2019-12406 are fixed in Apache-apache-cxf for Linux 3.2.11Linux
Vulnerabilities CVE-2019-12406 are fixed in Apache-apache-cxf for Linux 3.3.4Linux
Vulnerabilities CVE-2019-12406,CVE-2019-12419 are fixed in Apache - cxf for Linux 3.2.11Linux
Vulnerabilities CVE-2019-12406,CVE-2019-12419 are fixed in Apache - cxf for Linux 3.3.4Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234