Back to search
CVE-2025-48913
Published: Aug 8, 2025
Modified: Feb 26, 2026
PUBLISHED
Description
If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility. Users are recommended to upgrade to versions 3.6.8, 4.0.9 or 4.1.3, which fix this issue.
| Vendor | Product | Versions |
|---|---|---|
Apache Software Foundation | Apache CXF | affected 4.1.0 - < 4.1.3affected 4.0.0 - < 4.0.9affected 0 - < 3.6.8 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now