CVE Vulnerabilities

CVE-2015-5348

Published: Apr 15, 2016 | Modified: Apr 12, 2025
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
3.7 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in Camel routes, allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.

Affected Software

NameVendorStart VersionEnd Version
CamelApache2.6.0 (including)2.6.0 (including)
CamelApache2.7.0 (including)2.7.0 (including)
CamelApache2.7.1 (including)2.7.1 (including)
CamelApache2.7.2 (including)2.7.2 (including)
CamelApache2.7.3 (including)2.7.3 (including)
CamelApache2.7.4 (including)2.7.4 (including)
CamelApache2.7.5 (including)2.7.5 (including)
CamelApache2.8.0 (including)2.8.0 (including)
CamelApache2.8.1 (including)2.8.1 (including)
CamelApache2.8.2 (including)2.8.2 (including)
CamelApache2.8.3 (including)2.8.3 (including)
CamelApache2.8.4 (including)2.8.4 (including)
CamelApache2.8.5 (including)2.8.5 (including)
CamelApache2.8.6 (including)2.8.6 (including)
CamelApache2.9.0 (including)2.9.0 (including)
CamelApache2.9.1 (including)2.9.1 (including)
CamelApache2.9.2 (including)2.9.2 (including)
CamelApache2.9.3 (including)2.9.3 (including)
CamelApache2.9.4 (including)2.9.4 (including)
CamelApache2.9.5 (including)2.9.5 (including)
CamelApache2.9.6 (including)2.9.6 (including)
CamelApache2.9.7 (including)2.9.7 (including)
CamelApache2.9.8 (including)2.9.8 (including)
CamelApache2.10.0 (including)2.10.0 (including)
CamelApache2.10.1 (including)2.10.1 (including)
CamelApache2.10.2 (including)2.10.2 (including)
CamelApache2.10.3 (including)2.10.3 (including)
CamelApache2.10.4 (including)2.10.4 (including)
CamelApache2.10.5 (including)2.10.5 (including)
CamelApache2.10.6 (including)2.10.6 (including)
CamelApache2.10.7 (including)2.10.7 (including)
CamelApache2.11.0 (including)2.11.0 (including)
CamelApache2.11.1 (including)2.11.1 (including)
CamelApache2.11.2 (including)2.11.2 (including)
CamelApache2.11.3 (including)2.11.3 (including)
CamelApache2.11.4 (including)2.11.4 (including)
CamelApache2.12.0 (including)2.12.0 (including)
CamelApache2.12.1 (including)2.12.1 (including)
CamelApache2.12.2 (including)2.12.2 (including)
CamelApache2.12.3 (including)2.12.3 (including)
CamelApache2.12.4 (including)2.12.4 (including)
CamelApache2.12.5 (including)2.12.5 (including)
CamelApache2.13.0 (including)2.13.0 (including)
CamelApache2.13.1 (including)2.13.1 (including)
CamelApache2.13.2 (including)2.13.2 (including)
CamelApache2.13.3 (including)2.13.3 (including)
CamelApache2.13.4 (including)2.13.4 (including)
CamelApache2.14.0 (including)2.14.0 (including)
CamelApache2.14.1 (including)2.14.1 (including)
CamelApache2.14.2 (including)2.14.2 (including)
CamelApache2.14.3 (including)2.14.3 (including)
CamelApache2.14.4 (including)2.14.4 (including)
CamelApache2.15.0 (including)2.15.0 (including)
CamelApache2.15.1 (including)2.15.1 (including)
CamelApache2.15.2 (including)2.15.2 (including)
CamelApache2.15.3 (including)2.15.3 (including)
CamelApache2.15.4 (including)2.15.4 (including)
CamelApache2.16.0 (including)2.16.0 (including)
Red Hat JBoss Fuse 6.3RedHat*

References