Description
The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.
Mitigation
We recommend upgrading to a version of this component that is not vulnerable to this specific issue. If upgrading is not an option this vulnerability can be mitigated by removing URIMappingInterceptor from use or by utilizing WS-SecurityPolicy.
Ref: http://cxf.apache.org/cve-2012-5633.html