Skip to content

CVE-2014-0034

The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly validate SAML tokens when caching is enabled, which allows remote attackers to gain access via an invalid SAML token.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0186 (1.9%)
Percentile: 83.2%
EPSS: 2026-05-06

Affects

apache:cxfredhat:jboss_enterprise_application_platform

Technical description

The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly validate SAML tokens when caching is enabled, which allows remote attackers to gain access via an invalid SAML token.

Published: 7/7/2014, 2:55:03 PM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam