imPC@ndo IT

Tracker / CVE-2020-11973

CVE-2020-11973

Critical 9.8

Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.

Affected products and versions

apache camel · 2.22.0 → 2.25.0
apache camel · 3.0.0 → 3.1.0
oracle communications_diameter_signaling_router · 8.0.0 → 8.5.0
oracle enterprise_manager_base_platform
oracle flexcube_private_banking

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References