Apache CXF: Untrusted JMS configuration can lead to RCE
Vulnerability Description
If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility. Users are recommended to upgrade to versions 3.6.8, 4.0.9 or 4.1.3, which fix this issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-48913
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- M Bhatt (r34p3r) OWASP GenAI Security Project & Blake Gatto (b1oo) Shrewd Research
More from Apache Software Foundation
View All →Affected Vendor
Apache Software Foundation
View all reports →