First published: Tue Dec 13 2022(Updated: )
A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/eap7-apache-cxf | <0:3.4.10-1.redhat_00001.1.el8ea | 0:3.4.10-1.redhat_00001.1.el8ea |
redhat/eap7-apache-cxf | <0:3.4.10-1.redhat_00001.1.el9ea | 0:3.4.10-1.redhat_00001.1.el9ea |
redhat/eap7-apache-cxf | <0:3.4.10-1.redhat_00001.1.el7ea | 0:3.4.10-1.redhat_00001.1.el7ea |
redhat/rh-sso7-keycloak | <0:18.0.6-1.redhat_00001.1.el7 | 0:18.0.6-1.redhat_00001.1.el7 |
redhat/rh-sso7-keycloak | <0:18.0.6-1.redhat_00001.1.el8 | 0:18.0.6-1.redhat_00001.1.el8 |
redhat/rh-sso7-keycloak | <0:18.0.6-1.redhat_00001.1.el9 | 0:18.0.6-1.redhat_00001.1.el9 |
Apache CXF | <3.4.10 | |
Apache CXF | >=3.5.0<3.5.5 | |
IBM Watson Knowledge Catalog on-prem | <=4.x | |
redhat/Apache CXF | <3.5.5 | 3.5.5 |
redhat/Apache CXF | <3.4.10 | 3.4.10 |
<3.4.10 | ||
>=3.5.0<3.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-46364 is a server-side request forgery (SSRF) vulnerability found in Apache CXF.
CVE-2022-46364 occurs when parsing the href attribute of XOP:Include in MTOM requests in Apache CXF.
CVE-2022-46364 has a severity rating of 9.8 (Critical).
CVE-2022-46364 affects Apache CXF versions up to and including 3.5.5.
To fix CVE-2022-46364, upgrade Apache CXF to version 3.5.6 or higher.