CyberSec.Space Logo
返回 CVE 浏览器

CVE-2020-11972

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0960%
EPSS Percentile27.50th
Published2020年5月14日
Last Modified2024年11月21日

Vulnerability Description

Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.

Affected Platforms (CPE)

📦
Apache

Camel

>= 2.22.0 and <= 2.25.0
📦
Apache

Camel

>= 3.0.0 and <= 3.1.0
📦
Oracle

Communications Diameter Signaling Router

>= 8.0.0 and <= 8.2.2
📦
Oracle

Enterprise Manager Base Platform

= 13.3.0.0
📦
Oracle

Enterprise Manager Base Platform

= 13.4.0.0
📦
Oracle

Flexcube Private Banking

= 12.0.0
📦
Oracle

Flexcube Private Banking

= 12.1.0

References & Advisories

相关漏洞威胁