← Back to browse · API

CVE-2022-45378

Severity
CRITICAL
CVSS
9.8
EPSS
0.0227
Risk score
39.99
CISA KEV
No
PoC
No
Published
2022-11-14
Modified
2024-08-03
First seen
2026-08-08
Aliases
EUVD-2022-7266, GHSA-789V-H9HW-38PG
Products
Apache Software Foundation:Apache SOAP Apache SOAP 2.3
Sources
euvd EUVD-2022-7266

Description

In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invoke methods on the classpath that meet certain criteria. Depending on what classes are available on the classpath this might even lead to arbitrary remote code execution. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

References