Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-28752


A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted.


Published

2024-03-15T11:15:09.220

Last Modified

2025-06-27T15:06:40.040

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.3 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-918
  • Type: Secondary
    CWE-918

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache cxf < 3.5.8 Yes
Application apache cxf < 3.6.3 Yes
Application apache cxf < 4.0.4 Yes
Application netapp oncommand_workflow_automation - Yes
Application netapp ontap_tools 10 Yes

References