← back
CVE-2022-46364criticalCWE-918

Apache CXF SSRF Vulnerability

48Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 9.8epss 2.4%
from disclosure to weapon1201 days
Published on NVDDec 13
1st PoC+1201d
exploitation probability
2.4%top 17% of all CVEs
observed exploitation
nono source reports it
5 public exploit(s)
A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. 
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.