RMI and LDAP URL Configuration Vulnerability in Apache CXF
CVE-2025-48913

9.8CRITICAL

Key Information:

Vendor

Apache

Vendor
CVE Published:
8 August 2025

What is CVE-2025-48913?

A vulnerability exists in Apache CXF where untrusted users could configure JMS to utilize RMI or LDAP URLs, potentially enabling unauthorized code execution capabilities. The interface has now been updated to restrict these protocols, addressing the risk associated with misconfigured JMS settings. Users are encouraged to upgrade to the latest releases including versions 3.6.8, 4.0.9, or 4.1.3 to mitigate this issue.

Affected Version(s)

Apache CXF 4.1.0 < 4.1.3

Apache CXF 4.0.0 < 4.0.9

Apache CXF 0 < 3.6.8

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

M Bhatt (r34p3r) OWASP GenAI Security Project & Blake Gatto (b1oo) Shrewd Research
.
CVE-2025-48913 : RMI and LDAP URL Configuration Vulnerability in Apache CXF