CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-28752

CVSS 9.3v3.1pub. 2024-03-15upd. 2025-06-27

A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted.

🤖 AI Analysis
How it works

The vulnerability is present only in configurations using Aegis DataBinding — the default databinding mechanism is not vulnerable. An attacker can prepare appropriately malicious input data and pass it to any web service built on Apache CXF with Aegis DataBinding, provided it accepts at least one parameter of any type. The server processes this data and may be induced to execute HTTP requests to internal or external resources that the attacker would not normally have access to.

Impact

An attacker can gain unauthorized access to internal network resources (SSRF), read sensitive information, and affect the integrity of operations performed by the server on behalf of the attacker. This can lead to exposure of internal infrastructure and escalation to further attacks on the internal network.

Mitigation & patch

Apache CXF should be updated to version 4.0.4, 3.6.3, or 3.5.8 (depending on the branch used). If an update is not immediately possible, consider switching to the default databinding mechanism instead of Aegis DataBinding. NetApp product users should apply patches according to the manufacturer's recommendations available at security.netapp.com.

Who is affected

Apache CXF in versions before 4.0.4, before 3.6.3, and before 3.5.8, only when Aegis DataBinding is used. It also affects NetApp products: OnCommand Workflow Automation and ONTAP Tools (versions specified in NetApp manufacturer references).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
  • Apache Cxf

    APP
    Apache
    < 3.5.83.6.0 – 3.6.3 (excl.)4.0.0 – 4.0.4 (excl.)
  • Netapp Oncommand Workflow Automation

    APP
    Netapp
    all versions
  • Netapp Ontap Tools

    APP
    Netapp
    10
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
SSRF
CWE
References

Related vulnerabilities

CVE-2021-44228CRITICAL10.0⚠ KEVPL ✓same product

Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup

CVE-2016-3427CRITICAL9.8⚠ KEVPL ✓same product

Krytyczna podatność RCE w Oracle Java SE i JRockit — komponent JMX

CVE-2026-61466CRITICAL9.1PL ✓same product

Apache CXF: brak walidacji scope w rejestracji klienta OAuth2

CVE-2026-63687CRITICAL9.1PL ✓same product

Apache CXF: podmiana parametrów PKCE i OIDC przez JWT w JwtRequestCodeFilter

CVE-2026-65583CRITICAL9.1PL ✓same product

Apache CXF: pominięcie walidacji tokenów OIDC umożliwia authentication bypass