CVE-2019-0188

Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
VendorProductVersion
apachecamel
𝑥
< 2.24.0
oracleenterprise_data_quality
11.1.1.9.0
oracleenterprise_manager_base_platform
13.3.0.0
oracleenterprise_manager_base_platform
13.4.0.0
oracleflexcube_private_banking
12.0.0
oracleflexcube_private_banking
12.1.0
oracleenterprise_repository
12.1.3.0.0
𝑥
= Vulnerable software versions
References