CVE-2022-45378

CRITICAL

Apache SOAP < 2.3 - Unauthenticated Remote Code Execution via RPCRouterServlet

Title source: llm
STIX 2.1

Description

In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invoke methods on the classpath that meet certain criteria. Depending on what classes are available on the classpath this might even lead to arbitrary remote code execution. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list
http://www.openwall.com/lists/oss-security/2022/11/14/4

Scores

CVSS v3 9.8
EPSS 0.0451
EPSS Percentile 89.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-306
Status published
Products (2)
apache/soap < 2.3
soap/soap 0.0.0Maven
Published Nov 14, 2022
Tracked Since Feb 18, 2026