Apache CXF contains a flaw that is triggered when an certain SupportingToken policy assertions are not properly read by a client when a Supporting Token is used to sign or encrypt certain parts of child policies of WS-SecurityPolicy 1.1. This may make it easier for an attacker to compromise a users system.
Upgrade to version 2.4.8, 2.5.4 or 2.6.1 or higher, as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.