VendorsApachecxf_fediz1.2.0
Vulnerabilities

Apache Software Foundation CXF Fediz 1.2.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2016-4464
The application plugins in Apache CXF Fediz 1.2.x before 1.2.3 and 1.3.x before 1.3.1 do not match SAML AudienceRestriction values against configured audience URIs, which might allow remote attackers to have bypass intended restrictions and have unspecified other impact via a crafted SAML token with a trusted signature.
Published 2016-09-21 · Modified
9.8EPSS 0.040
CVE-2015-5175
Application plugins in Apache CXF Fediz before 1.1.3 and 1.2.x before 1.2.1 allow remote attackers to cause a denial of service.
Published 2017-06-07 · Modified
7.5EPSS 0.109