CVE-2025-48913
Last modified
CVE-2025-48913 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility. Users are recommended to upgrade to versions 3.6.8, 4.0.9 or 4.1.3, which fix this issue.. EPSS estimates a 0.74% chance of exploitation in the next 30 days.
Description
If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility. Users are recommended to upgrade to versions 3.6.8, 4.0.9 or 4.1.3, which fix this issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Cxf | < 3.6.8 |
| Apache | Cxf | >= 4.0.0, < 4.0.9 |
| Apache | Cxf | >= 4.1.0, < 4.1.3 |
References
- https://lists.apache.org/thread/f1nv488ztc0js4g5ml2v88mzkzslyh83Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-48913?
How severe is CVE-2025-48913?
How do I fix CVE-2025-48913?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-48908Ability Auto Startup service vulnerability in the foundation…6.7
- CVE-2025-48909Bypass vulnerability in the device management channel Impact…7.1
- CVE-2025-4891A vulnerability was found in code-projects Police Station Ma…7.8
- CVE-2025-48910Buffer overflow vulnerability in the DFile module Impact: Su…5.5
- CVE-2025-48911Vulnerability of improper permission assignment in the note …8.2
- CVE-2025-48912An authenticated malicious actor using specially crafted req…6.5
- CVE-2025-48914Improper Neutralization of Input During Web Page Generation …8.6
- CVE-2025-48915Improper Neutralization of Input During Web Page Generation …8.6
- CVE-2025-48916Missing Authorization vulnerability in Drupal Bookable Calen…6.5
- CVE-2025-48917Improper Neutralization of Input During Web Page Generation …5
- CVE-2025-48918Improper Neutralization of Input During Web Page Generation …8.8
- CVE-2025-48919Improper Neutralization of Input During Web Page Generation …5
Are you affected by CVE-2025-48913?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
