CVE-2025-64408
19.11.2025, 11:15
Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) throughuser-controllable URL parameters. These vulnerabilities affect allapplications using Causeway's ViewModel functionality and can be exploitedby authenticated attackers to execute arbitrary code with applicationprivileges. This issue affects all current versions. Users are recommended to upgrade to version 3.5.0, which fixes the issue.Enginsight
| Vendor | Product | Version |
|---|---|---|
| apache | causeway | 2.0.0 ≤ 𝑥 < 3.5.0 |
| apache | causeway | 4.0.0:m1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration