cbcvebase.
CVE-2025-48913
published 2025-08-08

CVE-2025-48913: If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities…

PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.79%
52.6th percentile
If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility. Users are recommended to upgrade to versions 3.6.8, 4.0.9 or 4.1.3, which fix this issue.

Affected

11 ranges
VendorProductVersion rangeFixed in
apachecxf< 3.6.83.6.8
apachecxf< 3.6.113.6.11
apachecxf
apachecxf>= 4.0.0 < 4.0.94.0.9
apachecxf>= 4.0.0 < 4.1.64.1.6
apachecxf>= 4.1.0 < 4.1.34.1.3
apache_software_foundationapache_cxf< 3.6.113.6.11
apache_software_foundationapache_cxf< 4.1.74.1.7
apache_software_foundationapache_cxf>= 4.0.0 < 4.1.64.1.6
apache_software_foundationapache_cxf>= 4.2.0 < 4.2.14.2.1
apache_software_foundationapache_cxf>= 4.2.0 < 4.2.24.2.2

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvelistv5v3.19.8CRITICALCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
ghsa9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.