CVE-2017-12633 PUBLISHED CVSS 7.5 HIGH

The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.

EPSS 3.41% · 87.3th percentile

Risk Scores

CVSS v2.0
7.5
EPSS Score
3.41%
87.3th percentile

Affected Products

VendorProductVersions
apachecamel2.20.0, 2.0.0
Apache Software FoundationApache CamelThe unsupported Camel 2.x (2.18 and earlier) versions may be also affected., 2.19.0 to 2.19.3, 2.20.0
Mavenorg.apache.camel:camel-hessian2.20.0, 2.20.0, 2.0

Timeline

References

Open in Interactive Console →