CVE-2019-0188
28.05.2019, 19:29
Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed.Enginsight
Vendor | Product | Version |
---|---|---|
apache | camel | 𝑥 < 2.24.0 |
oracle | enterprise_data_quality | 11.1.1.9.0 |
oracle | enterprise_manager_base_platform | 13.3.0.0 |
oracle | enterprise_manager_base_platform | 13.4.0.0 |
oracle | flexcube_private_banking | 12.0.0 |
oracle | flexcube_private_banking | 12.1.0 |
oracle | enterprise_repository | 12.1.3.0.0 |
𝑥
= Vulnerable software versions
References