Описание
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
A flaw was found in Apache CXF. Untrusted users, if allowed to configure Java Message Service (JMS) for Apache CXF, can exploit this vulnerability to achieve remote code execution (RCE). This issue arises from an incomplete fix for a prior security flaw, indicating an alternative path that could lead to code execution.
Отчет
This is an Important flaw in Apache CXF where an incomplete fix for a prior vulnerability allows remote code execution. Exploitation requires that untrusted users have permissions to configure Java Message Service (JMS) within the Apache CXF environment, which is not a default configuration in Red Hat products. Successful exploitation could lead to arbitrary code execution with the privileges of the affected service.
Меры по смягчению последствий
To mitigate this issue, ensure that only trusted users have permissions to configure Java Message Service (JMS) for Apache CXF. Restrict access to configuration files and management interfaces that control JMS settings. If JMS functionality is not required, consider disabling it to remove the attack vector.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Fuse 7 | cxf-rt-transports-jms | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 7 | cxf-rt-transports-jms | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 8 | cxf-rt-transports-jms | Affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | cxf-rt-transports-jms | Not affected | ||
| Red Hat Single Sign-On 7 | cxf-rt-transports-jms | Out of support scope | ||
| Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16 | cxf-rt-transports-jms | Fixed | RHSA-2026:37390 | 09.07.2026 |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
Apache CXF: Untrusted JMS configuration can lead to RCE
7.5 High
CVSS3