CVE-2015-5348

EUVD-2018-0474
Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in Camel routes, allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
Affected Products (NVD)
VendorProductVersion
apachecamel
2.6.0
apachecamel
2.7.0
apachecamel
2.7.1
apachecamel
2.7.2
apachecamel
2.7.3
apachecamel
2.7.4
apachecamel
2.7.5
apachecamel
2.8.0
apachecamel
2.8.1
apachecamel
2.8.2
apachecamel
2.8.3
apachecamel
2.8.4
apachecamel
2.8.5
apachecamel
2.8.6
apachecamel
2.9.0
apachecamel
2.9.1
apachecamel
2.9.2
apachecamel
2.9.3
apachecamel
2.9.4
apachecamel
2.9.5
apachecamel
2.9.6
apachecamel
2.9.7
apachecamel
2.9.8
apachecamel
2.10.0
apachecamel
2.10.1
apachecamel
2.10.2
apachecamel
2.10.3
apachecamel
2.10.4
apachecamel
2.10.5
apachecamel
2.10.6
apachecamel
2.10.7
apachecamel
2.11.0
apachecamel
2.11.1
apachecamel
2.11.2
apachecamel
2.11.3
apachecamel
2.11.4
apachecamel
2.12.0
apachecamel
2.12.1
apachecamel
2.12.2
apachecamel
2.12.3
apachecamel
2.12.4
apachecamel
2.12.5
apachecamel
2.13.0
apachecamel
2.13.1
apachecamel
2.13.2
apachecamel
2.13.3
apachecamel
2.13.4
apachecamel
2.14.0
apachecamel
2.14.1
apachecamel
2.14.2
apachecamel
2.14.3
apachecamel
2.14.4
apachecamel
2.15.0
apachecamel
2.15.1
apachecamel
2.15.2
apachecamel
2.15.3
apachecamel
2.15.4
apachecamel
2.16.0
𝑥
= Vulnerable software versions
Common Weakness Enumeration