CVE-2022-46364

CRITICAL

Apache CXF <3.5.5, <3.4.10 - SSRF

Title source: llm

Description

A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. 

Exploits (6)

nomisec WORKING POC 2 stars
by cybermaksx · poc
https://github.com/cybermaksx/CVE-2022-46364-Proof-of-the-concept
nomisec WORKING POC
by jwsly12 · poc
https://github.com/jwsly12/CVE-2022-46364-htb-ctf
nomisec WORKING POC
by 0xmid00 · poc
https://github.com/0xmid00/CVE-2022-46364-poc
nomisec WORKING POC
by Shashivanth009 · poc
https://github.com/Shashivanth009/CVE-2022-46364---Apache-CXF-XOP-Include-LFI-PoC
nomisec WORKING POC
by cybermaksxx · poc
https://github.com/cybermaksxx/CVE-2022-46364-Proof-of-the-concept
nomisec WORKING POC
by kasem545 · poc
https://github.com/kasem545/CVE-2022-46364-Poc

Scores

CVSS v3 9.8
EPSS 0.0008
EPSS Percentile 23.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-918
Status published
Products (2)
apache/cxf < 3.4.10
org.apache.cxf/cxf-core 0 - 3.4.10Maven
Published Dec 13, 2022
Tracked Since Feb 18, 2026