Description
A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. 
Published: 2022-12-13
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-7768 A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. 
Github GHSA Github GHSA GHSA-x3x3-qwjq-8gj4 Apache CXF Server-Side Request Forgery vulnerability
History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00124}

epss

{'score': 0.00089}


Tue, 22 Apr 2025 03:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 25 Nov 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat jboss Enterprise Application Platform Eus
CPEs cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7
cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7
Vendors & Products Redhat jboss Enterprise Application Platform Eus

Subscriptions

Apache Cxf
Redhat Camel Spring Boot Jboss Enterprise Application Platform Jboss Enterprise Application Platform Eus Jboss Enterprise Bpms Platform Jboss Fuse Migration Toolkit Applications Migration Toolkit Runtimes Red Hat Single Sign On Rhosemc
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2025-04-22T02:48:36.211Z

Reserved: 2022-12-02T08:07:46.894Z

Link: CVE-2022-46364

cve-icon Vulnrichment

Updated: 2024-08-03T14:31:46.249Z

cve-icon NVD

Status : Modified

Published: 2022-12-13T17:15:17.587

Modified: 2025-04-22T03:15:20.907

Link: CVE-2022-46364

cve-icon Redhat

Severity : Important

Publid Date: 2022-12-13T00:00:00Z

Links: CVE-2022-46364 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses