CVE-2016-6812

Description

The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists the names and absolute URL addresses of the available service endpoints. The module calculates the base URL using the current HttpServletRequest. The calculated base URL is used by FormattedServiceListWriter to build the service endpoint absolute URLs. If the unexpected matrix parameters have been injected into the request URL then these matrix parameters will find their way back to the client in the services list page which represents an XSS risk to the client.

Category

6.1
CVSS
Severity: Medium
CVSS 3.0 •
CVSS 2.0 •
EPSS 6.56% Top 10%
Vendor Advisory redhat.com Vendor Advisory apache.org Vendor Advisory apache.org
Affected: Apache Software Foundation Apache CXF
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2016-6812?
CVE-2016-6812 has been scored as a medium severity vulnerability.
How to fix CVE-2016-6812?
To fix CVE-2016-6812, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2016-6812 being actively exploited in the wild?
It is possible that CVE-2016-6812 is being exploited or will be exploited in a near future based on public information. According to its EPSS score, there is a ~7% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2016-6812?
CVE-2016-6812 affects Apache Software Foundation Apache CXF.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.