Field Assessment
AI analysis pending.
CVE
CVE-2014-0034
Severity
MEDIUM
CVSS
4.3
EPSS
7.41%
Apache
Original Filing — NVD Description
The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly validate SAML tokens when caching is enabled, which allows remote attackers to gain access via an invalid SAML token.