Show filters
54 Total Results
Displaying 51-54 of 54
Sort by:
Attacker Value
Unknown
CVE-2019-12419
Disclosure Date: November 06, 2019 (last updated November 08, 2023)
Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to somehow steal an authorization code issued to another client, then they could exploit this vulnerability to obtain an access token for the other client.
0
Attacker Value
Unknown
CVE-2019-12406
Disclosure Date: November 06, 2019 (last updated November 08, 2023)
Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility of a denial of service type attack, where a malicious user crafts a message containing a very large number of message attachments. From the 3.3.4 and 3.2.11 releases, a default limit of 50 message attachments is enforced. This is configurable via the message property "attachment-max-count".
0
Attacker Value
Unknown
CVE-2016-5482
Disclosure Date: October 25, 2016 (last updated November 25, 2024)
Unspecified vulnerability in the Oracle Commerce Guided Search component in Oracle Commerce 6.2.2, 6.3.0, 6.4.1.2, and 6.5.0 through 6.5.2 allows remote attackers to affect confidentiality and integrity via unknown vectors.
0
Attacker Value
Unknown
CVE-2015-0495
Disclosure Date: April 16, 2015 (last updated October 05, 2023)
Unspecified vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager component in Oracle Commerce Platform 3.x and 11.x allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Workbench.
0