AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-1954

MEDIUM · CVSS 5.3 EPSS 6.15%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-04-01 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.3. It affects Apache.

CVE
CVE-2020-1954
Severity
MEDIUM
CVSS
5.3
EPSS
6.15%
Apache

Original NVD Description

Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.

Related CVEs

Other vulnerabilities affecting the same vendor(s)