Important Apache CXF Vulnerabilities Demand Immediate Action
ID: d0f4e577-92b8-54d6-8356-f6b650909304
STIX ID: report--d0f4e577-92b8-54d6-8356-f6b650909304
Feed Name: securityonline.info
Threat Score
Security researchers disclosed multiple critical vulnerabilities in the Apache CXF services framework — including a JNDI injection enabling unauthorized code execution, a WS JSON metadata validation bypass, an inverted IP-binding OAuth2 check, and an XXE via unhardended SAXParserFactory — affecting many applications; vendors have released fixes and users are urged to upgrade to versions 4.2.2 or 4.1.7 immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
