PT-2022-27480 · Apache · Apache Soap

Tsungshu Chiu

·

Published

2022-11-14

·

Updated

2024-08-03

·

CVE-2022-45378

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache SOAP (affected versions not specified)
Description The default configuration of Apache SOAP includes an RPCRouterServlet that is available without authentication, allowing an attacker to invoke methods on the classpath that meet certain criteria. Depending on the classes available on the classpath, this could lead to arbitrary remote code execution. This issue only affects products that are no longer supported by the maintainer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Improper Authentication

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2022-45378
GHSA-789V-H9HW-38PG

Affected Products

Apache Soap