Man-in-the-Middle (MitM) attack in Apache CXF - CVE-2020-1954

 

Man-in-the-Middle (MitM) attack in Apache CXF - CVE-2020-1954

Published: April 2, 2020


Vulnerability identifier: #VU26530
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1954
CWE-ID: CWE-300
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a man-in-the-middle (MitM) attack.

The vulnerability exists in the JMX Integration when the "createMBServerConnectorFactory" property of the default InstrumentationManagerImpl is not disabled. A remote attacker on the same host can perform a man-in-the-middle attack and gain access to all of the information that is sent and received over JMX. 


Affected software

Apache CXF
Dell Support Assist Enterprise
Integrated Diameter Intelligence Hub (IDIH)
Oracle Communications Session Route Manager
Oracle Communications Element Manager
Oracle Communications Session Report Manager
Enterprise Manager Base Platform
IBM Security Verify Governance
PeopleSoft Enterprise PeopleTools
IBM Security Guardium
IBM TRIRIGA Application Platform

How to mitigate CVE-2020-1954

Install updates from vendor's website.

Apache CXF - addressed in versions 3.2.13, 3.3.6
Dell Support Assist Enterprise - update to 4.00.06.00
IBM TRIRIGA Application Platform - addressed in versions 3.6.1.3, 3.7.0.1, 3.8.0.1, 4.0.2, 4.1.1
IBM Security Verify Governance - update to 10.0.1.0.5

External References

Related Security Bulletins