CVE-2020-11973
9.8
CRITICAL · CVSS 3.1 · EPSS 6.8% (pctl 94)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 6.76% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-502 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2020-05-14 |
| Last modified | 2026-06-17 |
Affected (4)
| Vendor | Product |
|---|---|
| apache | camel |
| oracle | communications diameter signaling router |
| oracle | enterprise manager base platform |
| oracle | flexcube private banking |
References
- http://www.openwall.com/lists/oss-security/2020/05/14/9
- https://camel.apache.org/security/CVE-2020-11973.html
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
- http://www.openwall.com/lists/oss-security/2020/05/14/9
- https://camel.apache.org/security/CVE-2020-11973.html
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
→ the Explorer · watch your stack · NVD