<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:10:05 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-00626</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-00626</link>
      <description>bdu:2020-00626</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-00626</guid>
    </item>
    <item>
      <title>certfr-2018-avi-589 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2018-avi-589</link>
      <description>certfr-2018-avi-589</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2018-avi-589</guid>
    </item>
    <item>
      <title>cnvd-2018-12672</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2018-12672</link>
      <description>cnvd-2018-12672</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2018-12672</guid>
    </item>
    <item>
      <title>EUVD-2026-185081</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-185081</link>
      <description>EUVD-2026-185081</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-185081</guid>
    </item>
    <item>
      <title>fkie_cve-2018-8039</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-8039</link>
      <description>&lt;p&gt;It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via &amp;#39;System.setProperty(&amp;#34;java.protocol.handler.pkgs&amp;#34;, &amp;#34;com.sun.net.ssl.internal.www.protocol&amp;#34;);&amp;#39;. When this system property is set, CXF uses some reflection to try to make the HostnameVerifier work with the old com.sun.net.ssl.HostnameVerifier interface. However, the default HostnameVerifier implementation in CXF does not implement the method in this interface, and an exception is thrown. However, in Apache CXF prior to 3.2.5 and 3.1.16 the exception is caught in the reflection code and not properly propagated. What this means is that if you are using the com.sun.net.ssl stack with CXF, an error with TLS hostname verification will not be thrown, leaving a CXF client subject to man-in-the-middle attacks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via &amp;#39;System.setProperty(&amp;#34;java.protocol.handler.pkgs&amp;#34;, &amp;#34;com.sun.net.ssl.internal.www.protocol&amp;#34;);&amp;#39;. When this system property is set, CXF uses some reflection to try to make the HostnameVerifier work with the old com.sun.net.ssl.HostnameVerifier interface. However, the default HostnameVerifier implementation in CXF does not implement the method in this interface, and an exception is thrown. However, in Apache CXF prior to 3.2.5 and 3.1.16 the exception is caught in the reflection code and not properly propagated. What this means is that if you are using the com.sun.net.ssl stack with CXF, an error with TLS hostname verification will not be thrown, leaving a CXF client subject to man-in-the-middle attacks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-8039</guid>
    </item>
    <item>
      <title>GHSA-jc7r-v6fg-2gpf — Apache CXF TLS hostname verification does not work correctly with com.sun.net.ssl.*</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jc7r-v6fg-2gpf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.cxf:cxf-rt-transports-http, Maven: org.apache.cxf:apache-cxf&lt;/p&gt;
&lt;p&gt;It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via &amp;#39;System.setProperty(&amp;#34;java.protocol.handler.pkgs&amp;#34;, &amp;#34;com.sun.net.ssl.internal.www.protocol&amp;#34;);&amp;#39;. When this system property is set, CXF uses some reflection to try to make the HostnameVerifier work with the old com.sun.net.ssl.HostnameVerifier interface. However, the default HostnameVerifier implementation in CXF does not implement the method in this interface, and an exception is thrown. However, in Apache CXF prior to 3.2.5 and 3.1.16 the exception is caught in the reflection code and not properly propagated. What this means is that if you are using the com.sun.net.ssl stack with CXF, an error with TLS hostname verification will not be thrown, leaving a CXF client subject to man-in-the-middle attacks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.cxf:cxf-rt-transports-http, Maven: org.apache.cxf:apache-cxf&lt;/p&gt;
&lt;p&gt;It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via &amp;#39;System.setProperty(&amp;#34;java.protocol.handler.pkgs&amp;#34;, &amp;#34;com.sun.net.ssl.internal.www.protocol&amp;#34;);&amp;#39;. When this system property is set, CXF uses some reflection to try to make the HostnameVerifier work with the old com.sun.net.ssl.HostnameVerifier interface. However, the default HostnameVerifier implementation in CXF does not implement the method in this interface, and an exception is thrown. However, in Apache CXF prior to 3.2.5 and 3.1.16 the exception is caught in the reflection code and not properly propagated. What this means is that if you are using the com.sun.net.ssl stack with CXF, an error with TLS hostname verification will not be thrown, leaving a CXF client subject to man-in-the-middle attacks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jc7r-v6fg-2gpf</guid>
    </item>
    <item>
      <title>gsd-2018-8039</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-8039</link>
      <description>gsd-2018-8039</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-8039</guid>
    </item>
    <item>
      <title>RHSA-2018:2276 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.1 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2018:2276</link>
      <description>&lt;p&gt;apache-cxf: TLS hostname verification does not work correctly with com.sun.net.ssl.* wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (Zip Slip)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;apache-cxf: TLS hostname verification does not work correctly with com.sun.net.ssl.* wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (Zip Slip)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2018:2276</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1594 — IBM Tivoli Network Manager: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1594</link>
      <description>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in IBM Tivoli Network Manager ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen, seine Privilegien auszuweiten, Daten zu manipulieren, nicht spezifizierte Auswirkungen zu verursachen und einen Cross-Site-Scripting-Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in IBM Tivoli Network Manager ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen, seine Privilegien auszuweiten, Daten zu manipulieren, nicht spezifizierte Auswirkungen zu verursachen und einen Cross-Site-Scripting-Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1594</guid>
    </item>
  </channel>
</rss>
