CVE-2022-46364

Description

A SSRF vulnerability in parsing thehref attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.118

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2022-46364 are fixed in IBM WebSphere 23.0.0.2Windows
Vulnerabilities CVE-2022-46364,CVE-2022-46363 are fixed in Apache-CXF-Core 3.4.10Windows
Vulnerabilities CVE-2022-46364,CVE-2022-46363 are fixed in Apache-CXF-Core 3.5.5Windows
Multiple Vulnerabilities are affected in IBM TXSeries for Multiplatforms 8.1Windows
Multiple Vulnerabilities are affected in IBM TXSeries for Multiplatforms 9.1Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 20.0.0.2Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.2.0.0Windows
Multiple vulnerabilities are affected in Oracle Commerce Platform 11.3.0Windows
Multiple vulnerabilities are affected in Oracle Commerce Platform 11.3.1Windows
Multiple vulnerabilities are affected in Oracle Commerce Platform 11.3.2Windows
Multiple vulnerabilities are affected in Oracle BI Publisher 6.4.0.0.0Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 18.0.0.2Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 19.0.0.3Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 21.0.3.1Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 22.0.2Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.2.3Windows
Multiple Vulnerabilities are affected in IBM Tivoli Application Dependency Discovery Manager 7.3.0.10Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.9Windows
Multiple Vulnerabilities are affected in IBM TXSeries for Multiplatforms 8.2Windows
Vulnerabilities CVE-2022-45787,CVE-2022-46364,CVE-2022-48285,CVE-2023-0482 are affected in IBM Cognos Analytics 12.0Windows
Vulnerabilities CVE-2022-46364,CVE-2022-46363 are fixed in Apache-CXF-Core for Linux 3.4.10Linux
Vulnerabilities CVE-2022-46364,CVE-2022-46363 are fixed in Apache-CXF-Core for Linux 3.5.5Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234