CVE-2022-46364Disclosure(apache / cxf)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache cxf systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cxf

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Exploit: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-07); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
cxf

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-07: 1Mentions · 2026-07-04: 1Patch / Workaround · 2026-07-04: 1Technical Details · 2026-05-07: 1Technical Details · 2026-07-04: 105-0707-04
Signal classification2 categories
Disclosure
150.0%
Exploit
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-071
Disclosure1
2026-07-041
Exploit1
Full discourse2 posts
  • 1337@iamvivekz
    Disclosure

    🔓 Rooted DevArea on @HackTheBox! Anon FTP → JAR decompile → CVE-2022-46364 (CXF LFI) → CVE-2025-54123 (HoverFly RCE) → Binary hijack → ROOT 👑 Full writeup 👇 📝 Medium: https://medium.com/@DaakuDaddy/devarea-walthrough-hack-the-box-08d9a27663b1 💼 LinkedIn: https://www.linkedin.com/in/vivekgoswmii #HackTheBox #ctf https://labs.hackthebox.com/achievement/machine/2310429/859

    Post summary

    The post outlines a CTF walk‑through that chains two CVEs (CXF LFI and HoverFly RCE) to achieve root, linking to a full write‑up, but it does not provide exploit code or patch details.

    001402.8K
    79 followersView on X
  • DFIR Radar@DFIR_Radar
    Exploit

    HTB DevArea (retired): a four-layer Linux attack chain walks through CVE-2022-46364 arbitrary file read, Hoverfly CVE-2025-54123 command injection, Flask cookie forgery, and a symlink-chain bypass in a sudo script. - CVE-2022-46364 (Apache CXF before 3.4.10/3.5.5) lets an attacker embed an xop:Include href="file:///..." element inside a multipart/related MTOM SOAP request. The server fetches the path, base64-encodes the bytes, and reflects them in the response. The employee-service.jar on the anonymous FTP server fingered the vulnerable CXF 3.2.14 version before a packet was sent. Reading /proc/self/cmdline and /proc/[pid]/cmdline exposed the Hoverfly process command line in plaintext, leaking creds: admin:O7IJ27MyyXiU. - CVE-2025-54123 (Hoverfly 1.11.3): a PUT to /api/v2/hoverfly/middleware with JSON body {"binary":"/bin/bash","script":"..."} passes user-controlled values directly to exec.Command without sanitization. The server runs the script as the service user, giving a shell as dev_ryan. The fix in 1.12.0 disables the middleware API by default. - The SysWatch Flask app stores its SECRET_KEY in /etc/syswatch.env with chmod 755 (world-readable). Reading that file via the CXF file-read lets an attacker forge a valid Flask session cookie (flask-unsign or Flask's own SecureCookieSessionInterface). #DFIR_Radar

    Post summary

    The post details a four‑layer attack chain using CVE‑2022‑46364 and CVE‑2025‑54123, describing file‑read and command‑injection exploitation steps, and notes a mitigation in Hoverfly 1.12.0.

    10010233
    1.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachecxf---

Explore more