CVE Vulnerabilities

CVE-2015-5348

Published: Apr 15, 2016 | Modified: Nov 07, 2023
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
3.7 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Ubuntu

Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in Camel routes, allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.

Affected Software

Name Vendor Start Version End Version
Camel Apache 2.6.0 (including) 2.6.0 (including)
Camel Apache 2.7.0 (including) 2.7.0 (including)
Camel Apache 2.7.1 (including) 2.7.1 (including)
Camel Apache 2.7.2 (including) 2.7.2 (including)
Camel Apache 2.7.3 (including) 2.7.3 (including)
Camel Apache 2.7.4 (including) 2.7.4 (including)
Camel Apache 2.7.5 (including) 2.7.5 (including)
Camel Apache 2.8.0 (including) 2.8.0 (including)
Camel Apache 2.8.1 (including) 2.8.1 (including)
Camel Apache 2.8.2 (including) 2.8.2 (including)
Camel Apache 2.8.3 (including) 2.8.3 (including)
Camel Apache 2.8.4 (including) 2.8.4 (including)
Camel Apache 2.8.5 (including) 2.8.5 (including)
Camel Apache 2.8.6 (including) 2.8.6 (including)
Camel Apache 2.9.0 (including) 2.9.0 (including)
Camel Apache 2.9.1 (including) 2.9.1 (including)
Camel Apache 2.9.2 (including) 2.9.2 (including)
Camel Apache 2.9.3 (including) 2.9.3 (including)
Camel Apache 2.9.4 (including) 2.9.4 (including)
Camel Apache 2.9.5 (including) 2.9.5 (including)
Camel Apache 2.9.6 (including) 2.9.6 (including)
Camel Apache 2.9.7 (including) 2.9.7 (including)
Camel Apache 2.9.8 (including) 2.9.8 (including)
Camel Apache 2.10.0 (including) 2.10.0 (including)
Camel Apache 2.10.1 (including) 2.10.1 (including)
Camel Apache 2.10.2 (including) 2.10.2 (including)
Camel Apache 2.10.3 (including) 2.10.3 (including)
Camel Apache 2.10.4 (including) 2.10.4 (including)
Camel Apache 2.10.5 (including) 2.10.5 (including)
Camel Apache 2.10.6 (including) 2.10.6 (including)
Camel Apache 2.10.7 (including) 2.10.7 (including)
Camel Apache 2.11.0 (including) 2.11.0 (including)
Camel Apache 2.11.1 (including) 2.11.1 (including)
Camel Apache 2.11.2 (including) 2.11.2 (including)
Camel Apache 2.11.3 (including) 2.11.3 (including)
Camel Apache 2.11.4 (including) 2.11.4 (including)
Camel Apache 2.12.0 (including) 2.12.0 (including)
Camel Apache 2.12.1 (including) 2.12.1 (including)
Camel Apache 2.12.2 (including) 2.12.2 (including)
Camel Apache 2.12.3 (including) 2.12.3 (including)
Camel Apache 2.12.4 (including) 2.12.4 (including)
Camel Apache 2.12.5 (including) 2.12.5 (including)
Camel Apache 2.13.0 (including) 2.13.0 (including)
Camel Apache 2.13.1 (including) 2.13.1 (including)
Camel Apache 2.13.2 (including) 2.13.2 (including)
Camel Apache 2.13.3 (including) 2.13.3 (including)
Camel Apache 2.13.4 (including) 2.13.4 (including)
Camel Apache 2.14.0 (including) 2.14.0 (including)
Camel Apache 2.14.1 (including) 2.14.1 (including)
Camel Apache 2.14.2 (including) 2.14.2 (including)
Camel Apache 2.14.3 (including) 2.14.3 (including)
Camel Apache 2.14.4 (including) 2.14.4 (including)
Camel Apache 2.15.0 (including) 2.15.0 (including)
Camel Apache 2.15.1 (including) 2.15.1 (including)
Camel Apache 2.15.2 (including) 2.15.2 (including)
Camel Apache 2.15.3 (including) 2.15.3 (including)
Camel Apache 2.15.4 (including) 2.15.4 (including)
Camel Apache 2.16.0 (including) 2.16.0 (including)
Red Hat JBoss Fuse 6.3 RedHat *

References