Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action String that is inconsistent with the message body.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.apache.cxf:cxf(Maven) | 0 | 2.4.9 | N/A |
| org.apache.cxf:cxf(Maven) | 2.5.0 | 2.5.5 | N/A |
| org.apache.cxf:cxf(Maven) | 2.6.0 | 2.6.2 | N/A |
CVSS Metrics