CVE-2022-46364
published 2022-12-13CVE-2022-46364: A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to…
PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.93%
77.7th percentile
A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | < 3.4.10 | 3.4.10 |
| apache | cxf | >= 3.5.0 < 3.5.5 | 3.5.5 |
| apache_software_foundation | apache_cxf | < 3.5.5 | 3.5.5 |
| apache_software_foundation | apache_cxf | < 3.4.10 | 3.4.10 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Commerce Risk Matrix: Endeca Integration (Apache CXF) — CVE-2022-46364
vendor_oracle·2024-04-15·CVSS 9.8
CVE-2022-46364 [CRITICAL] Oracle Oracle Commerce Risk Matrix: Endeca Integration (Apache CXF) — CVE-2022-46364
Oracle Oracle Commerce Risk Matrix: Endeca Integration (Apache CXF) vulnerability
CVE: CVE-2022-46364
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Messaging Store (Apache CXF) — CVE-2022-46364
vendor_oracle·2023-07-15·CVSS 9.8
CVE-2022-46364 [CRITICAL] Oracle Oracle Communications Applications Risk Matrix: Messaging Store (Apache CXF) — CVE-2022-46364
Oracle Oracle Communications Applications Risk Matrix: Messaging Store (Apache CXF) vulnerability
CVE: CVE-2022-46364
CVSS: 9.8
Protocol: SMTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Communications Risk Matrix: Virtual Network Function Manager (Apache CXF) — CVE-2022-46364
vendor_oracle·2023-04-15·CVSS 9.8
CVE-2022-46364 [CRITICAL] Oracle Oracle Communications Risk Matrix: Virtual Network Function Manager (Apache CXF) — CVE-2022-46364
Oracle Oracle Communications Risk Matrix: Virtual Network Function Manager (Apache CXF) vulnerability
CVE: CVE-2022-46364
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Red Hat
CXF: SSRF Vulnerability
vendor_redhat·2022-12-13·CVSS 9.8
CVE-2022-46364 [CRITICAL] CWE-918 CXF: SSRF Vulnerability
CXF: SSRF Vulnerability
A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type.
A SSRF vulnerability was found in Apache CXF. This issue occurs when parsing the href attribute of XOP:Include in MTOM requests, allowing an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type.
Statement: Red Hat Integration Camel Quarkus does not support CXF extensions and so is affected at a reduced impact of Moderate.
The RHSSO server does not ship Apache CXF. The component mentioned in CVE-2022-46364 is a transitive dependency coming from Fuse adapters and the test suite.
P
GHSA
Apache CXF Server-Side Request Forgery vulnerability
ghsa·2022-12-13
CVE-2022-46364 [CRITICAL] CWE-918 Apache CXF Server-Side Request Forgery vulnerability
Apache CXF Server-Side Request Forgery vulnerability
A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type.
OSV
Apache CXF Server-Side Request Forgery vulnerability
osv·2022-12-13
CVE-2022-46364 [CRITICAL] Apache CXF Server-Side Request Forgery vulnerability
Apache CXF Server-Side Request Forgery vulnerability
A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type.
No detection rules found.
No public exploits indexed.
CTF
web_thedarkportal / README
ctf_writeups·2023·CVSS 9.8
[CRITICAL] web_thedarkportal / README
# The Dark Portal Web, 304 points
_Writeup by [@bluepichu](https://github.com/bluepichu), [@nneonneo](https://github.com/nneonneo), and [@f0xtr0t](https://github.com/jaybosamiya)_
> "The dark portal is fulfilled with unlimited chaos, twisted runes, and endless darkness, you shall follow the guidance of your mentor Apache.CXF to find it. Then, try your best to pass through..."
This challenge has no source download, so all we have to go on is the description and the service itself. The service appears to be a static page with two links:
- One links to a WSDL file that describes a very simple API.
- The other goes to "the front of the dark portal", a page that makes a request to `/7he_d4rk_p0rt4l` and inserts it onto the page.
Since the description and service both mention Apache CXF and
Qualys
Oracle Patch Tuesday, July 2023 Security Update Review
blogs_qualys·2023-07-19
Oracle Patch Tuesday, July 2023 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
Oracle has released its third quarterly edition of Critical Patch Update, which contains a group of patches for 508 security vulnerabilities. Some of the vulnerabilities addressed this month impact more than one product. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During Q3 2023 Oracle Critical Patch Update, the Oracle Financial Services Applications received the highest number of 147 patches, constituting 29% of the total patches released. Oracle Communications and Oracle Fusion Middleware followed, with
Qualys
Oracle Patch Tuesday, July 2023 Security Update Review | Qualys
blogs_qualys·2023-07-19
Oracle Patch Tuesday, July 2023 Security Update Review | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
Oracle has released its third quarterly edition of Critical Patch Update, which contains a group of patches for 508 security vulnerabilities. Some of the vulnerabilities addressed this month impact more than one product. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During Q3 2023 Oracle Critical Patch Update, the Oracle Financial Services Applications received the highest number of 147 patches, constituting 29% of the total patches released. Oracle Communications and Oracle Fusion Middleware followe
Qualys
Oracle Security Updates: Critical Patch April 2023 Advisory | Qualys
blogs_qualys·2023-04-19
Oracle Security Updates: Critical Patch April 2023 Advisory | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
Oracle has released the second quarterly edition of Critical Patch Update, which contains a group of patches for 433 security vulnerabilities. Some of the vulnerabilities addressed this month impact various products. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During Q2 2023 Oracle Critical Patch Update, the Oracle Communications product suite recorded the highest number of patches at 77, constituting 17% of the total patches released. The Oracle Financial Services Applications and Oracle Fusion Mi
Qualys
Oracle Patch Tuesday April 2023 Security Update Review
blogs_qualys·2023-04-19
Oracle Patch Tuesday April 2023 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
Oracle has released the second quarterly edition of Critical Patch Update, which contains a group of patches for 433 security vulnerabilities. Some of the vulnerabilities addressed this month impact various products. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During Q2 2023 Oracle Critical Patch Update, the Oracle Communications product suite recorded the highest number of patches at 77, constituting 17% of the total patches released. The Oracle Financial Services Applications and Oracle Fusion Middlewar
2022-12-13
Published