Lucene search

K
cvelistApacheCVELIST:CVE-2017-12633
HistoryNov 15, 2017 - 12:00 a.m.

CVE-2017-12633

2017-11-1500:00:00
apache
www.cve.org
1

9.5 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.7%

The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.

CNA Affected

[
  {
    "product": "Apache Camel",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "2.19.0 to 2.19.3"
      },
      {
        "status": "affected",
        "version": "2.20.0"
      },
      {
        "status": "affected",
        "version": "The unsupported Camel 2.x (2.18 and earlier) versions may be also affected."
      }
    ]
  }
]

9.5 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.7%