First published: Wed Jun 07 2017(Updated: )
Application plugins in Apache CXF Fediz before 1.1.3 and 1.2.x before 1.2.1 allow remote attackers to cause a denial of service.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.apache.cxf.fediz:fediz-core | >=1.2<1.2.1 | 1.2.1 |
maven/org.apache.cxf.fediz:fediz-core | <1.1.3 | 1.1.3 |
maven/org.apache.cxf.fediz:fediz-idp | >=1.2<1.2.1 | 1.2.1 |
maven/org.apache.cxf.fediz:fediz-idp | <1.1.3 | 1.1.3 |
Apache CXF Fediz | <=1.1.2 | |
Apache CXF Fediz | =1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2015-5175 is considered to be medium due to its potential to cause denial of service.
To fix CVE-2015-5175, upgrade to Apache CXF Fediz version 1.1.3 or 1.2.1 or later.
Apache CXF Fediz versions prior to 1.1.3 and 1.2.x before 1.2.1 are affected by CVE-2015-5175.
Yes, CVE-2015-5175 can be exploited by remote attackers to create a denial of service.
CVE-2015-5175 facilitates a denial of service attack on applications using vulnerable plugins in Apache CXF Fediz.