Back

CVE-2019-12419

CRITICAL

Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to somehow steal an authorization code issued to another client, then they could exploit this vulnerability to obtain an access token for the other client.

Published: Nov 6, 2019 Modified: Jun 17, 2026
CWE-863

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (7)

Vendor Product Version
apache cxf * ≥ 3.2.0 < 3.2.11
apache cxf * ≥ 3.3.0 < 3.3.4
oracle commerce_guided_search 11.3.2
oracle enterprise_manager_base_platform 13.2.1.0
oracle flexcube_private_banking 12.0.0
oracle flexcube_private_banking 12.1.0
oracle retail_order_broker 15.0

GitHub Security Advisory GHSA-cw6w-q88j-6mqf

Potential session hijack in Apache CXF

maven org.apache.cxf:cxf < 3.2.11 Fixed: 3.2.11
maven org.apache.cxf:cxf >= 3.3.0, < 3.3.4 Fixed: 3.3.4

References (28)

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 13.84%

Top 4% most likely to be exploited

Threat Score 43.4 / 100

Data Sources

NVD EPSS GitHub