The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbitrary Java methods via a crafted message.
The MITRE CVE dictionary describes this issue as:
Find out more about CVE-2014-0003 from the MITRE CVE dictionary dictionary and NIST NVD.
Base Score | 6 |
---|---|
Base Metrics | AV:N/AC:M/Au:S/C:P/I:P/A:P |
Access Vector | Network |
Access Complexity | Medium |
Authentication | Single |
Confidentiality Impact | Partial |
Integrity Impact | Partial |
Availability Impact | Partial |
Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).
Platform | Errata | Release Date |
---|---|---|
Fuse MQ Enterprise 7.1.0 | RHSA-2014:0452 | 2014-04-30 |
RHOSE Client 2.0 (activemq) | RHSA-2014:0245 | 2014-03-03 |
Fuse Management Console 7.1.0 | RHSA-2014:0452 | 2014-04-30 |
RHOSE Client 1.2 (activemq) | RHSA-2014:0254 | 2014-03-05 |
Fuse ESB Enterprise 7.1.0 | RHSA-2014:0452 | 2014-04-30 |
Platform | Package | State |
---|---|---|
Red Hat OpenShift Enterprise 2 | camel | Affected |
Red Hat OpenShift Enterprise 1 | camel | Affected |
Red Hat JBoss Fuse Service Works 6 | Camel | Affected |
Red Hat JBoss BRMS 6 | Camel | Affected |
Red Hat JBoss BPMS 6 | Camel | Affected |