CVE-2014-0035

medium Apache
CVSS v3 Base Score
4.3
AV:N/AC:M/Au:N/C:P/I:N/A:N
EPSS Score
1.0%
Exploitation probability in 30 days
Top 23% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
M
Confidentiality
P
Integrity
None
Availability
None
Published: July 7, 2014 (4329 days ago)
Last Modified: May 6, 2026
Vendor: Apache
Source: NVD

Description

The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning is enabled and the UsernameToken policy is set to an EncryptedSupportingToken, transmits the UsernameToken in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.

CWE

CWE-310

Affected Products

apache cxfredhat jboss enterprise application platform

References