peter bassill · operator
$ cve CVE-2019-12419 JSON

CVE-2019-12419

9.8
CRITICAL · CVSS 3.1 · EPSS 13.8% (pctl 96)

Patch early

EPSS 13.8% — above the 10% action threshold.

Description

Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to somehow steal an authorization code issued to another client, then they could exploit this vulnerability to obtain an access token for the other client.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS13.84% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-863
On CISA KEVno
Public exploitnone known
Published2019-11-06
Last modified2026-06-17

Affected (5)

VendorProduct
apachecxf
oraclecommerce guided search
oracleenterprise manager base platform
oracleflexcube private banking
oracleretail order broker

References

→ the Explorer  ·  watch your stack  ·  NVD