imPC@ndo IT

Tracker / CVE-2019-0188

CVE-2019-0188

High 7.5

Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed.

Affected products and versions

apache camel · … → 2.24.0
oracle enterprise_data_quality
oracle enterprise_manager_base_platform
oracle enterprise_repository
oracle flexcube_private_banking

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References