Man-in-the-Middle (MitM) attack in Apache CXF - CVE-2020-1954
Published: April 2, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a man-in-the-middle (MitM) attack.
The vulnerability exists in the JMX Integration when the "createMBServerConnectorFactory" property of the default InstrumentationManagerImpl is not disabled. A remote attacker on the same host can perform a man-in-the-middle attack and gain access to all of the information that is sent and received over JMX.
Affected software
Dell Support Assist Enterprise
Integrated Diameter Intelligence Hub (IDIH)
Oracle Communications Session Route Manager
Oracle Communications Element Manager
Oracle Communications Session Report Manager
Enterprise Manager Base Platform
IBM Security Verify Governance
PeopleSoft Enterprise PeopleTools
IBM Security Guardium
IBM TRIRIGA Application Platform
How to mitigate CVE-2020-1954
Dell Support Assist Enterprise - update to 4.00.06.00
IBM TRIRIGA Application Platform - addressed in versions 3.6.1.3, 3.7.0.1, 3.8.0.1, 4.0.2, 4.1.1
IBM Security Verify Governance - update to 10.0.1.0.5
External References
Related Security Bulletins
- Man-in-the-Middle (MitM) attack in Apache CXF
- Multiple vulnerabilities in Integrated Diameter Intelligence Hub (IDIH)
- Multiple vulnerabilities in Oracle Communications Session Route Manager
- Multiple vulnerabilities in Oracle Communications Session Report Manager
- Multiple vulnerabilities in Oracle Communications Element Manager
- Multiple vulnerabilities in Enterprise Manager Base Platform
- Multiple vulnerabilities in PeopleSoft Enterprise PeopleTools
- IBM TRIRIGA Application Platform update for Apache CXF
- Multiple vulnerabilities in IBM Security Guardium
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in Dell Support Assist Enterprise