CVE-2012-3451
Remote web-service operation execution in Apache CXF
EPSS 10.0%
Description
Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action String that is inconsistent with the message body.
How to fix CVE-2012-3451
To remediate CVE-2012-3451, upgrade the affected package to a fixed version below.
- Maven/org.apache.cxf:cxf—upgrade to 2.4.9 or later
Is CVE-2012-3451 being exploited?
Moderate — EPSS is 10.0%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 2.4.9