VYPR
Medium severity6.1NVD Advisory· Published Jan 16, 2020· Updated Jun 17, 2026

CVE-2019-17573

CVE-2019-17573

Description

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into the web page. Please note that the attack exploits a feature which is not typically not present in modern browsers, who remove dot segments before sending the request. However, Mobile applications may be vulnerable.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.cxf:apache-cxfMaven
< 3.2.123.2.12
org.apache.cxf:apache-cxfMaven
>= 3.3.0, < 3.3.53.3.5
org.apache.cxf:cxfMaven
< 3.2.123.2.12
org.apache.cxf:cxfMaven
>= 3.3.0, < 3.3.53.3.5

Affected products

17
  • Apache/Cxf2 versions
    cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*range: >=3.2.0,<=3.2.12
    • (no CPE)range: All versions of Apache CXF prior to 3.3.5 and 3.2.12.
  • cpe:2.3:a:oracle:commerce_guided_search:11.3.2:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:communications_element_manager:8.1.1:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:oracle:communications_element_manager:8.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:communications_element_manager:8.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:communications_element_manager:8.2.1:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:communications_session_report_manager:8.1.1:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:oracle:communications_session_report_manager:8.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:communications_session_report_manager:8.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:communications_session_report_manager:8.2.1:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:communications_session_route_manager:8.1.1:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:oracle:communications_session_route_manager:8.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:communications_session_route_manager:8.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:communications_session_route_manager:8.2.1:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:retail_order_broker:15.0:*:*:*:*:*:*:*
  • ghsa-coords2 versions
    < 3.2.12+ 1 more
    • (no CPE)range: < 3.2.12
    • (no CPE)range: < 3.2.12

Patches

Vulnerability mechanics

References

27

News mentions

0

No linked articles in our index yet.