Server-Side Request Forgery (SSRF) in Apache CXF - CVE-2024-29736

 

Server-Side Request Forgery (SSRF) in Apache CXF - CVE-2024-29736

Published: September 18, 2024


Vulnerability identifier: #VU97457
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2024-29736
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform SSRF attacks.

The vulnerability exists due to insufficient validation of user-supplied input passed via the WADL stylesheet parameter. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.

Successful exploitation of this vulnerability requires that a custom stylesheet parameter is configured.


Affected software

Apache CXF
Oracle BI Publisher
IBM Business Automation Manager Open Editions
NetWorker Management Console (NMC)
IBM Tivoli Application Dependency Discovery Manager
Oracle Communications Cloud Native Core Unified Data Repository
Red Hat Camel for Spring Boot
Juniper Secure Analytics (JSA)
EMC NetWorker Server
IBM Cloud Pak for Business Automation

How to mitigate CVE-2024-29736

Install updates from vendor's website.

Apache CXF - addressed in versions 3.5.9, 3.6.4, 4.0.5
IBM Business Automation Manager Open Editions - update to 8.0.7
Red Hat Camel for Spring Boot - update to 3.20.7
Juniper Secure Analytics (JSA) - update to 7.5.0 UP11 IF03
NetWorker Management Console (NMC) - update to 19.10.0.5
EMC NetWorker Server - update to 19.10.0.5
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF004, 24.0.1-IF001

External References

Related Security Bulletins