668
VMScore

CVE-2015-5344

Published: 03/02/2016 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The camel-xstream component in Apache Camel prior to 2.15.5 and 2.16.x prior to 2.16.1 allow remote malicious users to execute arbitrary commands via a crafted serialized Java object in an HTTP request.

Vulnerable Product Search on Vulmon Subscribe to Product

apache camel

apache camel 2.16.0

Vendor Advisories

It was found that Apache Camel's camel-xstream component was vulnerable to Java object deserialization This vulnerability permits deserialization of data which could lead to information disclosure, code execution, or other possible attacks ...