CVE-2020-11972
EUVD-2021-091014.05.2020, 17:15
Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | camel | 2.22.0 ≤ 𝑥 ≤ 2.25.0 |
| apache | camel | 3.0.0 ≤ 𝑥 ≤ 3.1.0 |
| oracle | communications_diameter_signaling_router | 8.0.0 ≤ 𝑥 ≤ 8.2.2 |
| oracle | enterprise_manager_base_platform | 13.3.0.0 |
| oracle | enterprise_manager_base_platform | 13.4.0.0 |
| oracle | flexcube_private_banking | 12.0.0 |
| oracle | flexcube_private_banking | 12.1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References