The vendor explicitly identifies these products as affected by this CVE.
- cxf-rt-transports-jms as a component of Red Hat build of Apache Camel for Spring Boot 4
- cxf as a component of Red Hat JBoss Enterprise Application Platform 7
- cxf-rt-transports-jms as a component of Red Hat JBoss Enterprise Application Platform 7
- eap74-els-openjdk11-openshift-rhel8/eap74-els-openjdk11-openshift-rhel8 as a component of Red Hat JBoss Enterprise Application Platform 7
- eap74-els-openjdk17-openshift-rhel8/eap74-els-openjdk17-openshift-rhel8 as a component of Red Hat JBoss Enterprise Application Platform 7
- eap74-els-openjdk8-openshift-rhel8/eap74-els-openjdk8-openshift-rhel8 as a component of Red Hat JBoss Enterprise Application Platform 7
- jboss-eap-7-eap74-els-openjdk17-openshift-rhel8/jboss-eap-7-eap74-els-openjdk17-openshift-rhel8 as a component of Red Hat JBoss Enterprise Application Platform 7
- jboss-eap-7-eap74-els-openjdk8-openshift-rhel8/jboss-eap-7-eap74-els-openjdk8-openshift-rhel8 as a component of Red Hat JBoss Enterprise Application Platform 7
- cxf-rt-transports-jms as a component of Red Hat JBoss Enterprise Application Platform 8
- cxf-rt-transports-jms as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack
- cxf-rt-transports-jms as a component of Red Hat Single Sign-On 7
- Summary
- A flaw was found in Apache CXF. The Java Message Service (JMS) transport component improperly deserializes inbound JMS ObjectMessages without type restrictions. A remote attacker can exploit this by sending a specially crafted message to the service's JMS destination. This vulnerability could lead to a denial of service or, in certain configurations, enable remote code execution on the affected system.
- Remediation
- To mitigate this vulnerability, disable ObjectMessage deserialization in Apache CXF's JMS transport. This can typically be achieved through a configuration setting provided by the Apache CXF framework. Consult the Apache CXF documentation for specific instructions on how to disable ObjectMessage deserialization in your deployment. Disabling this feature may impact applications that rely on ObjectMessage for legitimate data transfer.
