Apache CXF contains a flaw that is triggered by an error when WS-SecurityPolicy 1.1 policies are specified as children of Supporting Tokens. This may allow an attacker to bypass certain policies when elements are signed or encrypted by a token.
Upgrade to version 2.4.8, 2.5.4 or 2.6.1 or higher, as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.