{"id":"CVE-2020-1954","details":"Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.","aliases":["GHSA-ffm7-7r8g-77xm"],"modified":"2026-07-08T05:56:34.620725499Z","published":"2020-04-01T21:15:14.597Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0.0"},{"last_affected":"8.2.2"}],"source":"CPE_RANGE","vendor_product":"oracle:communications_diameter_signaling_router"},{"vendor_product":"oracle:communications_diameter_signaling_router_idih:","cpes":["cpe:2.3:a:oracle:communications_diameter_signaling_router_idih\\::*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0.0"},{"last_affected":"8.2.2"}],"source":"CPE_RANGE"},{"extracted_events":[{"introduced":"8.2.0"},{"last_affected":"8.2.2"},{"introduced":"8.2.0"},{"last_affected":"8.2.2"}],"source":"CPE_RANGE","vendor_product":"oracle:communications_element_manager","cpes":["cpe:2.3:a:oracle:communications_element_manager:*:*:*:*:*:*:*:*"]},{"vendor_product":"oracle:communications_session_report_manager","cpes":["cpe:2.3:a:oracle:communications_session_report_manager:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.2.0"},{"last_affected":"8.2.2"},{"introduced":"8.2.0"},{"last_affected":"8.2.2"}],"source":"CPE_RANGE"},{"extracted_events":[{"introduced":"8.2.0"},{"last_affected":"8.2.2"}],"source":"CPE_RANGE","vendor_product":"oracle:communications_session_route_manager","cpes":["cpe:2.3:a:oracle:communications_session_route_manager:*:*:*:*:*:*:*:*"]},{"vendor_product":"oracle:enterprise_manager_base_platform","cpes":["cpe:2.3:a:oracle:enterprise_manager_base_platform:13.2.1.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"13.2.1.0"},{"last_affected":"13.2.1.0"},{"introduced":"13.2.1.0"},{"last_affected":"13.2.1.0"}],"source":"CPE_STRING"},{"extracted_events":[{"introduced":"8.56"},{"last_affected":"8.56"},{"introduced":"8.56"},{"last_affected":"8.56"}],"source":"CPE_STRING","vendor_product":"oracle:peoplesoft_enterprise_peopletools","cpes":["cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:*"]}]},"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3E"},{"type":"ADVISORY","url":"http://cxf.apache.org/security-advisories.data/CVE-2020-1954.txt.asc?version=1&modificationDate=1585730169000&api=v2"},{"type":"FIX","url":"https://security.netapp.com/advisory/ntap-20220210-0001/"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuoct2020.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/cxf","events":[{"introduced":"0"},{"fixed":"a3ec49229acfb484617091bc1f0cb597e6db9230"},{"introduced":"8f90e00177d464541e99ed61238cbc52cff0846d"},{"fixed":"92d34cab5f11a74908294c2953fc4f42c8366a90"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"3.2.13"},{"introduced":"3.3.0"},{"fixed":"3.3.6"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*"}}],"versions":["cxf-3.3.5","cxf-3.2.12","cxf-3.2.11","cxf-3.3.4","cxf-3.3.3","cxf-3.2.10","cxf-3.3.2","cxf-3.2.9","cxf-3.3.1","cxf-3.2.8","cxf-3.3.0","cxf-3.2.7","cxf-3.2.6","cxf-3.2.5","cxf-3.2.4","cxf-3.2.3","cxf-3.2.2","cxf-3.2.1","cxf-3.2.0","cxf-3.1.4","cxf-3.1.3","cxf-3.1.2","cxf-3.1.1","cxf-3.1.0","cxf-3.0.0","cxf-3.0.0-milestone2","cxf-2.7.2","cxf-2.7.1","cxf-2.7.0","cxf-2.6.1","cxf-2.6.0","cxf-2.5.1","cxf-2.5.0","cxf-2.4.0","cxf-2.3.0","cxf-2.2.2","cxf-2.2.1","cxf-2.2","cxf-2.1.2","cxf-2.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-1954.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}