CVE-2022-45378

CVE-2022-45378: Apache SOAP allows unauthenticated users to potentially invoke arbitrary code

Vendor Apache Software Foundation
Product Apache SOAP
Weakness CWE-306 · Missing auth
Published November 14, 2022
Last update August 3, 2024

CVSS base score

What the vulnerability does

Description

In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invoke methods on the classpath that meet certain criteria. Depending on what classes are available on the classpath this might even lead to arbitrary remote code execution. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Key dates

Disclosure timeline

November 14, 2022 CVE published
August 3, 2024 Record updated