Vulnerabilities > Apache > CXF > 2.6.14
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-08-10 | CVE-2016-8739 | XXE vulnerability in Apache CXF The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. | 7.5 |
2017-08-10 | CVE-2016-6812 | Cross-site Scripting vulnerability in Apache CXF The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists the names and absolute URL addresses of the available service endpoints. | 6.1 |