CVE Database
/

CVE-2025-48913

Back to search

CVE-2025-48913

Published: Aug 8, 2025

Modified: Feb 26, 2026

PUBLISHED

Description

If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility. Users are recommended to upgrade to versions 3.6.8, 4.0.9 or 4.1.3, which fix this issue.

VendorProductVersions

Apache Software Foundation

Apache CXF

affected
4.1.0 - < 4.1.3
affected
4.0.0 - < 4.0.9
affected
0 - < 3.6.8

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now