Insufficiently protected credentials in Apache CXF - CVE-2019-12423
Published: May 12, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access ti sensitive information.
The vulnerability exists due to the application allows a client to obtain the keys from a JWK keystore file, by setting the configuration parameter "rs.security.keystore.type" to "jwk". A remote non-authenticated attacker can obtain all private key and secret key credentials and gain unauthorized access to the application.
Affected software
Dell Support Assist Enterprise
Oracle FLEXCUBE Private Banking
Dell Secure Connect Gateway
Oracle Communications Session Report Manager
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Oracle Communications Session Route Manager
Oracle Communications Element Manager
IBM Security Guardium
Oracle Commerce Guided Search
How to mitigate CVE-2019-12423
Dell Support Assist Enterprise - update to 4.00.06.00
Dell Secure Connect Gateway - update to 5.12.00.10
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.8.0
External References
- http://cxf.apache.org/security-advisories.data/CVE-2019-12423.txt.asc?version=1&modificationDate=1579178393000&api=v2
- https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rd588ff96f18563aeb5f87ac8c6bce7aae86cb1a4d4be483f96e7208c@%3Cannounce.apache.org%3E
- https://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4@%3Ccommits.cxf.apache.org%3E
Related Security Bulletins
- Information disclosure in Apache CXF
- Multiple vulnerabilities in Oracle Communications Session Route Manager
- Multiple vulnerabilities in Oracle Communications Session Report Manager
- Multiple vulnerabilities in Oracle Communications Element Manager
- Multiple vulnerabilities in Oracle FLEXCUBE Private Banking
- Multiple vulnerabilities in Red Hat Process Automation Manager
- Multiple vulnerabilities in Oracle Commerce Guided Search
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- Multiple vulnerabilities in IBM Security Guardium
- Multiple vulnerabilities in Dell Support Assist Enterprise