Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2015-5348

Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in Camel routes, allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.

CVSS v3:

  • Severity: High
  • Score: 8.1
  • AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2:

  • Severity: Medium
  • Score: 6.8
  • AV:N/AC:M/Au:N/C:P/I:P/A:P

CWEs:

Software From Fixed in
apache / camel 2.15.0 2.15.0.x
apache / camel 2.13.4 2.13.4.x
apache / camel 2.9.8 2.9.8.x
apache / camel 2.9.4 2.9.4.x
apache / camel 2.15.3 2.15.3.x
apache / camel 2.15.4 2.15.4.x
apache / camel 2.13.0 2.13.0.x
apache / camel 2.7.1 2.7.1.x
apache / camel 2.15.2 2.15.2.x
apache / camel 2.10.6 2.10.6.x
apache / camel 2.12.3 2.12.3.x
apache / camel 2.9.6 2.9.6.x
apache / camel 2.7.2 2.7.2.x
apache / camel 2.8.6 2.8.6.x
apache / camel 2.12.1 2.12.1.x
apache / camel 2.13.3 2.13.3.x
apache / camel 2.10.0 2.10.0.x
apache / camel 2.11.0 2.11.0.x
apache / camel 2.9.0 2.9.0.x
apache / camel 2.7.5 2.7.5.x
apache / camel 2.8.3 2.8.3.x
apache / camel 2.10.7 2.10.7.x
apache / camel 2.16.0 2.16.0.x
apache / camel 2.12.5 2.12.5.x
apache / camel 2.9.1 2.9.1.x
apache / camel 2.8.0 2.8.0.x
apache / camel 2.14.0 2.14.0.x
apache / camel 2.11.4 2.11.4.x
apache / camel 2.14.2 2.14.2.x
apache / camel 2.9.5 2.9.5.x
apache / camel 2.10.4 2.10.4.x
apache / camel 2.11.2 2.11.2.x
apache / camel 2.10.1 2.10.1.x
apache / camel 2.14.3 2.14.3.x
apache / camel 2.12.0 2.12.0.x
apache / camel 2.14.4 2.14.4.x
apache / camel 2.8.4 2.8.4.x
apache / camel 2.9.2 2.9.2.x
apache / camel 2.10.3 2.10.3.x
apache / camel 2.7.0 2.7.0.x
apache / camel 2.8.1 2.8.1.x
apache / camel 2.12.4 2.12.4.x
apache / camel 2.7.4 2.7.4.x
apache / camel 2.10.5 2.10.5.x
apache / camel 2.12.2 2.12.2.x
apache / camel 2.13.1 2.13.1.x
apache / camel 2.15.1 2.15.1.x
apache / camel 2.11.1 2.11.1.x
apache / camel 2.13.2 2.13.2.x
apache / camel 2.11.3 2.11.3.x
apache / camel 2.7.3 2.7.3.x
apache / camel 2.9.3 2.9.3.x
apache / camel 2.14.1 2.14.1.x
apache / camel 2.6.0 2.6.0.x
apache / camel 2.9.7 2.9.7.x
apache / camel 2.8.5 2.8.5.x
apache / camel 2.10.2 2.10.2.x
apache / camel 2.8.2 2.8.2.x
org.apache.camel / camel-jetty - 2.15.5
org.apache.camel / camel-jetty 2.16.0 2.16.0.x
org.apache.camel / camel-jetty 2.16.0 2.16.1
org.apache.camel / camel-servlet - 2.15.5
org.apache.camel / camel-servlet 2.16.0 2.16.0.x
org.apache.camel / camel-servlet 2.16.0 2.16.1