CyberSec.Space Logo
Back to CVE Browser

CVE-2020-11973

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0600%
EPSS Percentile35.41th
PublishedMay 14, 2020
Last ModifiedNov 21, 2024

Vulnerability Description

Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.

Affected Platforms (CPE)

πŸ“¦
Apache

Camel

>= 2.22.0 and <= 2.25.0
πŸ“¦
Apache

Camel

>= 3.0.0 and <= 3.1.0
πŸ“¦
Oracle

Communications Diameter Signaling Router

>= 8.0.0 and <= 8.5.0
πŸ“¦
Oracle

Enterprise Manager Base Platform

= 13.3.0.0
πŸ“¦
Oracle

Enterprise Manager Base Platform

= 13.4.0.0
πŸ“¦
Oracle

Flexcube Private Banking

= 12.0.0
πŸ“¦
Oracle

Flexcube Private Banking

= 12.1.0

References & Advisories

Related Vulnerabilities