CVE-2020-11971

Apache Camel's JMX is vulnerable to Rebind Flaw. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.x, 3.0.0 up to 3.1.0 is affected. Users should upgrade to 3.2.0.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
VendorProductVersion
apachecamel
2.22.0 ≤
𝑥
≤ 3.1.0
oraclecommunications_diameter_intelligence_hub
8.0.0 ≤
𝑥
≤ 8.1.0
oraclecommunications_diameter_intelligence_hub
8.2.0 ≤
𝑥
≤ 8.2.3
oraclecommunications_diameter_signaling_router
8.0.0 ≤
𝑥
≤ 8.2.2
oracleenterprise_manager_base_platform
13.3.0.0
oracleenterprise_manager_base_platform
13.4.0.0
oracleflexcube_private_banking
12.0.0
oracleflexcube_private_banking
12.1.0
𝑥
= Vulnerable software versions
References