HOMEVULNERABILITIESCVE-2020-1954
MEDIUM

CVE-2020-1954

NVD-CWE-noinfoPublished: April 1, 2020· Updated: Jun 17, 2026

5.3
CVSS v3.1

Official Description

Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.

NVD Source

Technical Analysis

CVE-2020-1954 requires adjacent network access, limiting remote exploitation but still posing risk in shared or local network environments.

The vulnerability requires no privileges and no user interaction, making it a prime target for automated exploitation campaigns and worm-like propagation.

A successful exploit results in complete confidentiality breach (data exposure), with a CVSS base score of 5.3.

CVSS v3.1 Vector Breakdown

Exploitability
Attack VectorAdjacent
Attack ComplexityHigh
Privileges Req.None
User InteractionNone
ScopeUnchanged
Impact
ConfidentialityHigh
IntegrityNone
AvailabilityNone
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Vendors & Products

Apache1 product(s)
cxf
netapp2 product(s)
oncommand workflow automationsnapmanager
Oracle7 product(s)
communications diameter signaling routercommunications element managercommunications session report managerenterprise manager base platformpeoplesoft enterprise peopletoolscommunications diameter signaling router idih\communications session route manager
Source: NVD CPE · 10 total CPE entries

Exploit & PoC Resources

NO KNOWN EXPLOITNo public exploit confirmed at this time
External links open in a new tab. Always verify in a controlled environment before use.

Official Patches & Advisories

All References (12)

Quick Facts

CVE IDCVE-2020-1954
CVSS Score5.3 / 10
SeverityMEDIUM
CISA KEVNo
Affected3 vendor(s)
PublishedApr 1, 2020

Related CVEs (NVD-CWE-noinfo)

Recommended Actions

  • Apply vendor patches immediately
  • Monitor CVE-2020-1954 in threat intel feeds
  • Review IDS/IPS signatures for exploitation attempts
Data sourced from NVD (NIST), CISA KEV, and EPSS (FIRST). Analysis generated by CTIWatch. CVE data is provided under the NVD usage policy.