RMI and LDAP URL Configuration Vulnerability in Apache CXF
CVE-2025-48913
9.8CRITICAL
What is CVE-2025-48913?
A vulnerability exists in Apache CXF where untrusted users could configure JMS to utilize RMI or LDAP URLs, potentially enabling unauthorized code execution capabilities. The interface has now been updated to restrict these protocols, addressing the risk associated with misconfigured JMS settings. Users are encouraged to upgrade to the latest releases including versions 3.6.8, 4.0.9, or 4.1.3 to mitigate this issue.
Affected Version(s)
Apache CXF 4.1.0 < 4.1.3
Apache CXF 4.0.0 < 4.0.9
Apache CXF 0 < 3.6.8
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
M Bhatt (r34p3r) OWASP GenAI Security Project & Blake Gatto (b1oo) Shrewd Research