Vulnerability Name: | CVE-2020-11972 (CCN-181962) | ||||||||||||
Assigned: | 2020-05-14 | ||||||||||||
Published: | 2020-05-14 | ||||||||||||
Updated: | 2021-03-15 | ||||||||||||
Summary: | Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0. | ||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
8.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-502 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2020-11972 Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20200514 Re: [SECURITY] New security advisory CVE-2020-11972 released for Apache Camel Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20200514 [SECURITY] New security advisory CVE-2020-11972 released for Apache Camel Source: CCN Type: Apache Camel Web site Apache Camel Source: MISC Type: Vendor Advisory https://camel.apache.org/security/CVE-2020-11972.html Source: XF Type: UNKNOWN apache-cve202011972-code-exec(181962) Source: CCN Type: oss-sec Mailing List, Thu, 14 May 2020 14:24:06 +0000 (UTC) [SECURITY] New security advisory CVE-2020-11972 released for Apache Camel Source: CCN Type: oss-sec Mailing List, Thu, 14 May 2020 14:26:30 +0000 (UTC) Re: [SECURITY] New security advisory CVE-2020-11972 released for Apache Camel Source: CCN Type: IBM Security Bulletin 6232458 (Jazz for Service Management) IBM Jazz for Service Management is vulnerable to Apache Camel Core vulnerabilities Source: CCN Type: IBM Security Bulletin 6244498 (Tivoli Netcool/OMNIbus) Multiple vulnerabilities have been identified in Apache Camel shipped with IBM Netcool/OMNIbus Probe DSL Factory Framework Source: CCN Type: IBM Security Bulletin 6258035 (Operations Analytics Predictive Insights) Vulnerabilities in Apache Camel's JMX, Apache Camel RabbitMQ and Apache Camel Netty affects IBM Operations Analytics Predictive Insights (CVE-2020-11971, CVE-2020-11972, CVE-2020-11973) Source: CCN Type: IBM Security Bulletin 6340097 (Resilient OnPrem) IBM Resilient SOAR is Using Components with Known Vulnerabilities - Apache Camel ( CVE-2019-0188, CVE-2020-11972, CVE-2020-11973) Source: CCN Type: IBM Security Bulletin 6410788 (Data Risk Manager) IBM Data Risk Manager is affected by multiple vulnerabilities Source: MISC Type: Third Party Advisory https://www.oracle.com/security-alerts/cpujan2021.html Source: MISC Type: Third Party Advisory https://www.oracle.com/security-alerts/cpuoct2020.html | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |