CVE-2025-48913
published 2025-08-08CVE-2025-48913: If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities…
PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.79%
52.3th percentile
If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility.
Users are recommended to upgrade to versions 3.6.8, 4.0.9 or 4.1.3, which fix this issue.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | < 3.6.8 | 3.6.8 |
| apache | cxf | < 3.6.11 | 3.6.11 |
| apache | cxf | — | — |
| apache | cxf | >= 4.0.0 < 4.0.9 | 4.0.9 |
| apache | cxf | >= 4.0.0 < 4.1.6 | 4.1.6 |
| apache | cxf | >= 4.1.0 < 4.1.3 | 4.1.3 |
| apache_software_foundation | apache_cxf | < 3.6.11 | 3.6.11 |
| apache_software_foundation | apache_cxf | < 4.1.7 | 4.1.7 |
| apache_software_foundation | apache_cxf | >= 4.0.0 < 4.1.6 | 4.1.6 |
| apache_software_foundation | apache_cxf | >= 4.2.0 < 4.2.1 | 4.2.1 |
| apache_software_foundation | apache_cxf | >= 4.2.0 < 4.2.2 | 4.2.2 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvelistv5v3.19.8CRITICALCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
ghsa9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2hvc-5c6v-f533: The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead
ghsa_unreviewed·2026-05-26·CVSS 9.8
CVE-2026-44417 [CRITICAL] CWE-20 GHSA-2hvc-5c6v-f533: The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
GHSA
Apache CXF: Untrusted JMS configuration can lead to RCE
ghsa·2026-05-26·CVSS 9.8
CVE-2026-44417 [CRITICAL] CWE-20 Apache CXF: Untrusted JMS configuration can lead to RCE
Apache CXF: Untrusted JMS configuration can lead to RCE
The fix for CVE-2025-48913: `Apache CXF: Untrusted JMS configuration can lead to RCE` was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CVEList
Apache CXF: Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to RCE)
cvelistv5·2026-05-22·CVSS 9.8
CVE-2026-44417 [CRITICAL] CWE-20 Apache CXF: Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to RCE)
Apache CXF: Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to RCE)
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
GHSA
Apache CXF: Untrusted JMS configuration can lead to RCE
ghsa·2025-08-08
CVE-2025-48913 [MEDIUM] CWE-20 Apache CXF: Untrusted JMS configuration can lead to RCE
Apache CXF: Untrusted JMS configuration can lead to RCE
If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility.
Users are recommended to upgrade to versions 3.6.8, 4.0.9 or 4.1.3, which fix this issue.
OSV
Apache CXF: Untrusted JMS configuration can lead to RCE
osv·2025-08-08
CVE-2025-48913 [MEDIUM] Apache CXF: Untrusted JMS configuration can lead to RCE
Apache CXF: Untrusted JMS configuration can lead to RCE
If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility.
Users are recommended to upgrade to versions 3.6.8, 4.0.9 or 4.1.3, which fix this issue.
Red Hat
org.apache.cxf/cxf: CXF JMS Code Execution Vulnerability
vendor_redhat·2025-08-08·CVSS 9.8
CVE-2025-48913 [CRITICAL] CWE-20 org.apache.cxf/cxf: CXF JMS Code Execution Vulnerability
org.apache.cxf/cxf: CXF JMS Code Execution Vulnerability
If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility.
Users are recommended to upgrade to versions 3.6.8, 4.0.9 or 4.1.3, which fix this issue.
A flaw was found in org.apache.cxf/cxf, where untrusted users can configure JMS to allow the specification of RMI or LDAP URLs, possibly leading to code execution. This vulnerability allows an attacker to provide malicious protocol URLs during JMS configuration.
Statement: This flaw should be considered Important because the impact goes beyond a simple denial of service or configuration misuse. By al
No detection rules found.
No public exploits indexed.
Qualys
Oracle Critical Patch Update, April 2026 Security Update Review
blogs_qualys·2026-04-22
CVE-2025-6965 Oracle Critical Patch Update, April 2026 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Oracle released its second quarterly edition of this year’s Critical Patch Update. The update received patches for 481 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 139, constituting about 28% of the total patches released. Oracle Financial Services Applications and Oracle Fusion Middleware followed, with 75 and 59 security patches.
376 of the 481 security patches provided by the April Critical Patch Update (about 78%)
Bugzilla
CVE-2026-44417 org.apache.cxf/cxf-rt-transports-jms: Apache CXF: Remote Code Execution via untrusted JMS configuration
bugzilla·2026-05-22·CVSS 9.8
CVE-2026-44417 [CRITICAL] CVE-2026-44417 org.apache.cxf/cxf-rt-transports-jms: Apache CXF: Remote Code Execution via untrusted JMS configuration
CVE-2026-44417 org.apache.cxf/cxf-rt-transports-jms: Apache CXF: Remote Code Execution via untrusted JMS configuration
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
Bugzilla
CVE-2025-48913 org.apache.cxf/cxf: CXF JMS Code Execution Vulnerability
bugzilla·2025-08-08·CVSS 9.8
CVE-2025-48913 [CRITICAL] CVE-2025-48913 org.apache.cxf/cxf: CXF JMS Code Execution Vulnerability
CVE-2025-48913 org.apache.cxf/cxf: CXF JMS Code Execution Vulnerability
If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility.
Users are recommended to upgrade to versions 3.6.8, 4.0.9 or 4.1.3, which fix this issue.
Discussion:
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 8.0.9
Via RHSA-2025:17318 https://access.redhat.com/errata/RHSA-2025:17318
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Via RHSA
2025-08-08
Published