Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed.
2019-05-28T19:29:02.550
2024-11-21T04:16:26.513
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | camel | < 2.24.0 | Yes |
Application | oracle | enterprise_data_quality | 11.1.1.9.0 | Yes |
Application | oracle | enterprise_manager_base_platform | 13.3.0.0 | Yes |
Application | oracle | enterprise_manager_base_platform | 13.4.0.0 | Yes |
Application | oracle | flexcube_private_banking | 12.0.0 | Yes |
Application | oracle | flexcube_private_banking | 12.1.0 | Yes |
Application | oracle | enterprise_repository | 12.1.3.0.0 | Yes |