Impact
The vulnerability is an incomplete patch to a prior advisory that allows code execution when untrusted users configure JMS for Apache CXF. Attackers who can supply or alter JMS configuration data can trigger remote code execution due to insufficient input validation, as captured by CWE‑20 and CWE‑502. The flaw can be exploited through JMS configuration interfaces exposed to non‑privileged users. Users are advised to upgrade to Apache CXF 4.2.2, 4.1.7, or 3.6.12, which address the issue.
Affected Systems
Affected systems are installations of Apache CXF that permit untrusted users to provide JMS configuration data. The advisory recommends upgrading to Apache CXF 4.2.2 or 4.1.7 to remediate the flaw. Any prior release that has not applied the patch is vulnerable, regardless of the specific version number; the most recent official fix is provided in the cited versions.
Risk and Exploitability
The CVSS score of 8.1 denotes a high severity, indicating that a successful exploit could lead to complete system compromise. The EPSS score of less than 1% suggests that the probability of exploitation in the wild is currently low, but the high severity justifies immediate action. The vulnerability is not listed in the CISA KEV catalog, meaning no known active exploitation has been observed, yet this does not diminish the urgency of patching. Attackers likely need access to the JMS configuration interface; thus environments that allow untrusted users to supply JMS configuration are the most vulnerable. The combination of a high severity flaw, even with low exploitation probability, means that prompt remediation is essential.
OpenCVE Enrichment