← back
CVE-2017-5653

CVE-2017-5653

8Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 11%
exploitation probability
11%top 4% of all CVEs
observed exploitation
nono source reports it
JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which allows remote attackers to spoof servers.