VDB
RHSA-2023%3A0164
RHSA-2023%3A0164
PUBLISHED
CVSS 9.800000190734863 CRITICAL
A SSRF vulnerability was found in Apache CXF. This issue occurs when parsing the href attribute of XOP:Include in MTOM requests, allowing an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type.
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | EAP 7.4 async |
Timeline
- Jan 12, 2023 CVE Published
- Mar 27, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2023:0164 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=securityPatches&product=appplatform&version=7.4 advisory
- https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.4/ advisory
- https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.4/html-single/installation_guide/ advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2155682 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_0164.json advisory
- https://access.redhat.com/security/cve/CVE-2022-46364 advisory
- https://www.cve.org/CVERecord?id=CVE-2022-46364 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-46364 advisory
- https://cxf.apache.org/security-advisories.data/CVE-2022-46364.txt?version=1&modificationDate=1670944472739&api=v2 advisory