Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2020-13954
Java vulnerability analysis and mitigation

Overview

Apache CXF versions prior to 3.4.1 and 3.3.8 contain a reflected Cross-Site Scripting (XSS) vulnerability (CVE-2020-13954). By default, Apache CXF creates a /services page containing a listing of available endpoint names and addresses. This webpage is vulnerable to a reflected XSS attack via the styleSheetPath parameter, which allows malicious actors to inject JavaScript into the web page (Apache Advisory).

Technical details

The vulnerability exists in the services listing page of Apache CXF, specifically in the handling of the styleSheetPath parameter. When a malicious actor provides crafted input through this parameter, it can result in JavaScript code being injected and executed in the context of other users' browsers. This is a separate issue from the previously reported CVE-2019-17573 (MITRE CVE).

Impact

A successful exploitation of this vulnerability could allow attackers to execute arbitrary JavaScript code in the context of other users' browsers who visit the affected services page. This could potentially lead to theft of sensitive information, session hijacking, or other client-side attacks (Apache Advisory).

Exploitability

The vulnerability is remotely exploitable without requiring authentication. An attacker can exploit this vulnerability by crafting a malicious URL that includes JavaScript code in the styleSheetPath parameter and convincing users to visit that URL (NVD).

Mitigation and workarounds

Users should upgrade to Apache CXF version 3.3.8 or 3.4.1 or later to address this vulnerability. Alternatively, as a workaround, administrators can disable the service listing altogether by setting the 'hide-service-list-page' servlet parameter to 'true' (Apache Advisory).

Community reactions

The vulnerability was reported by Ryan Lambeth and was addressed promptly by the Apache CXF team. Various organizations including NetApp and Oracle have issued security advisories acknowledging the vulnerability in their products that utilize Apache CXF (NetApp Advisory).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-69205HIGH8.7
  • Java logoJava
  • org.http4s:http4s-ember-core_3
NoYesSep 15, 2026
CVE-2026-88975HIGH7.5
  • Java logoJava
  • org.http4s:http4s-ember-core_2.13
NoYesSep 15, 2026
CVE-2026-69218HIGH7.5
  • Java logoJava
  • org.http4s:http4s-ember-core_2.13
NoYesSep 15, 2026
CVE-2026-69215MEDIUM6.8
  • Java logoJava
  • org.http4s:http4s-client_2.12
NoYesSep 15, 2026
CVE-2026-69206MEDIUM5.9
  • Java logoJava
  • org.http4s:http4s-ember-core_2.12
NoYesSep 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management