peter bassill · operator
$ cve CVE-2020-11973 JSON

CVE-2020-11973

9.8
CRITICAL · CVSS 3.1 · EPSS 6.8% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.76% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2020-05-14
Last modified2026-06-17

Affected (4)

VendorProduct
apachecamel
oraclecommunications diameter signaling router
oracleenterprise manager base platform
oracleflexcube private banking

References

→ the Explorer  ·  watch your stack  ·  NVD