Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-11972


Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.


Published

2020-05-14T17:15:12.117

Last Modified

2024-11-21T04:59:01.190

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-502

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache camel ≤ 2.25.0 Yes
Application apache camel ≤ 3.1.0 Yes
Application oracle communications_diameter_signaling_router ≤ 8.2.2 Yes
Application oracle enterprise_manager_base_platform 13.3.0.0 Yes
Application oracle enterprise_manager_base_platform 13.4.0.0 Yes
Application oracle flexcube_private_banking 12.0.0 Yes
Application oracle flexcube_private_banking 12.1.0 Yes

References