CVE-2025-64408

Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) throughuser-controllable URL parameters. These vulnerabilities affect allapplications using Causeway's ViewModel functionality and can be exploitedby authenticated attackers to execute arbitrary code with applicationprivileges.

This issue affects all current versions.

Users are recommended to upgrade to version 3.5.0, which fixes the issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
apacheCNA
---
---
CVEADP
---
---
CISA-ADPADP
6.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 72%
VendorProductVersion
apachecauseway
2.0.0 ≤
𝑥
< 3.5.0
apachecauseway
4.0.0:m1
𝑥
= Vulnerable software versions