Insufficiently protected credentials in Apache CXF - CVE-2019-12423

 

Insufficiently protected credentials in Apache CXF - CVE-2019-12423

Published: May 12, 2020


Vulnerability identifier: #VU27701
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12423
CWE-ID: CWE-522
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access ti sensitive information.

The vulnerability exists due to the application allows a client to obtain the keys from a JWK keystore file, by setting the configuration parameter "rs.security.keystore.type" to "jwk". A remote non-authenticated attacker can obtain all private key and secret key credentials and gain unauthorized access to the application.


Affected software

Apache CXF
Dell Support Assist Enterprise
Oracle FLEXCUBE Private Banking
Dell Secure Connect Gateway
Oracle Communications Session Report Manager
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Oracle Communications Session Route Manager
Oracle Communications Element Manager
IBM Security Guardium
Oracle Commerce Guided Search

How to mitigate CVE-2019-12423

Install updates from vendor's website.

Apache CXF - addressed in versions 3.2.12, 3.3.5
Dell Support Assist Enterprise - update to 4.00.06.00
Dell Secure Connect Gateway - update to 5.12.00.10
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.8.0

External References

Related Security Bulletins