CVE-2025-23184
published 2025-01-21CVE-2025-23184: A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.94%
77.9th percentile
A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | < 3.5.10 | 3.5.10 |
| apache | cxf | >= 3.6.0 < 3.6.5 | 3.6.5 |
| apache | cxf | >= 4.0.0 < 4.0.6 | 4.0.6 |
| apache_software_foundation | apache_cxf | < 3.5.10 | 3.5.10 |
| apache_software_foundation | apache_cxf | >= 3.6.0 < 3.6.5 | 3.6.5 |
| apache_software_foundation | apache_cxf | >= 4.0.0 < 4.0.6 | 4.0.6 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_oracle7.5MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Hitachi Energy Asset Suite
cisa_ics·2025-09-18·CVSS 7.1
[HIGH] Hitachi Energy Asset Suite
ICS Advisory
##
Hitachi Energy Asset Suite
Release DateSeptember 18, 2025
Alert CodeICSA-25-261-04
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.7
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: Asset Suite
- Vulnerabilities: Server-Side Request Forgery (SSRF), Deserialization of Untrusted Data, Cleartext Storage of Sensitive Information, Uncontrolled Resource Consumption, URL Redirection to Untrusted Site ('Open Redirect'), Improper Authentication
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow attackers to trigger resource consumption or information disclosure through SSRF in Apache XML Gra
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Maintenance (Apache CXF) — CVE-2025-23184
vendor_oracle·2025-07-15·CVSS 5.9
CVE-2025-23184 [MEDIUM] Oracle Oracle Financial Services Applications Risk Matrix: Maintenance (Apache CXF) — CVE-2025-23184
Oracle Oracle Financial Services Applications Risk Matrix: Maintenance (Apache CXF) vulnerability
CVE: CVE-2025-23184
CVSS: 5.9
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2025 (JUL 2025)
Oracle
Oracle Oracle Communications Risk Matrix: Signaling (Apache CXF) — CVE-2025-23184
vendor_oracle·2025-04-15·CVSS 7.5
CVE-2025-23184 [MEDIUM] Oracle Oracle Communications Risk Matrix: Signaling (Apache CXF) — CVE-2025-23184
Oracle Oracle Communications Risk Matrix: Signaling (Apache CXF) vulnerability
CVE: CVE-2025-23184
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2025 (APR 2025)
Red Hat
org.apache.cxf: Apache CXF: Denial of Service vulnerability with temporary files
vendor_redhat·2025-01-21·CVSS 5.9
CVE-2025-23184 [MEDIUM] CWE-400 org.apache.cxf: Apache CXF: Denial of Service vulnerability with temporary files
org.apache.cxf: Apache CXF: Denial of Service vulnerability with temporary files
A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).
A flaw was found in Apache CXF. In some edge cases with large data stream caching, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system and trigger a denial of service.
Package: org.apache.cxf/cxf-core (Logging Subsystem for Red Hat OpenShift) - Fix deferred
Package: org.apache.cxf/cxf-core (Red Hat build of Apache Camel 4 for Quarkus 3) - Fix deferred
Package: org.a
OSV
Apache CXF: Denial of Service vulnerability with temporary files
osv·2025-01-21
CVE-2025-23184 [HIGH] Apache CXF: Denial of Service vulnerability with temporary files
Apache CXF: Denial of Service vulnerability with temporary files
A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).
GHSA
Apache CXF: Denial of Service vulnerability with temporary files
ghsa·2025-01-21
CVE-2025-23184 [HIGH] CWE-400 Apache CXF: Denial of Service vulnerability with temporary files
Apache CXF: Denial of Service vulnerability with temporary files
A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).
No detection rules found.
No public exploits indexed.
https://lists.apache.org/thread/lfs8l63rnctnj2skfrxyys7v8fgnt122http://www.openwall.com/lists/oss-security/2025/01/20/3https://security.netapp.com/advisory/ntap-20250214-0003/https://www.vicarius.io/vsociety/posts/cve-2025-23184-detect-apache-cxf-vulnerabilityhttps://www.vicarius.io/vsociety/posts/cve-2025-23184-mitigate-apache-cxf-vulnerability
2025-01-21
Published