Vulnerabilities
Vulnerable Software
Apache:  >> Cxf  >> 4.0.7  Security Vulnerabilities
If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility. Users are recommended to upgrade to versions 3.6.8, 4.0.9 or 4.1.3, which fix this issue.
CVSS Score
9.8
EPSS Score
0.001
Published
2025-08-08


Contact Us

Shodan ® - All rights reserved