{
    "id": "CVE-2020-11972",
    "published": "2020-05-14 17:15:12",
    "last_modified": "2026-06-17 02:51:09",
    "cvss_score": "9.8",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-502",
    "description": "Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.",
    "epss_score": "0.05652",
    "epss_percentile": "0.92752",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 0,
    "updated_at": "2026-10-06 18:17:22",
    "priority": {
        "rank": 3,
        "label": "In your normal cycle",
        "why": "Critical by CVSS (9.8), but no sign of active exploitation."
    },
    "products": [
        {
            "vendor": "apache",
            "product": "camel"
        },
        {
            "vendor": "oracle",
            "product": "communications_diameter_signaling_router"
        },
        {
            "vendor": "oracle",
            "product": "enterprise_manager_base_platform"
        },
        {
            "vendor": "oracle",
            "product": "flexcube_private_banking"
        }
    ],
    "kev_detail": null,
    "exploits": [],
    "refs_list": [
        "http://www.openwall.com/lists/oss-security/2020/05/14/10",
        "http://www.openwall.com/lists/oss-security/2020/05/14/8",
        "https://camel.apache.org/security/CVE-2020-11972.html",
        "https://www.oracle.com/security-alerts/cpujan2021.html",
        "https://www.oracle.com/security-alerts/cpuoct2020.html",
        "http://www.openwall.com/lists/oss-security/2020/05/14/10",
        "http://www.openwall.com/lists/oss-security/2020/05/14/8",
        "https://camel.apache.org/security/CVE-2020-11972.html",
        "https://www.oracle.com/security-alerts/cpujan2021.html",
        "https://www.oracle.com/security-alerts/cpuoct2020.html"
    ]
}