Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0003

Опубликовано: 28 фев. 2014
Источник: redhat
CVSS2: 6
EPSS Средний

Описание

The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbitrary Java methods via a crafted message.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Web Server 1amq-6.0Affected
Red Hat JBoss Enterprise Web Server 1fuse-6.0Affected
Red Hat JBoss Enterprise Web Server 1fuse-esb-7.1Affected
Red Hat JBoss Enterprise Web Server 1fuse-mq-7.1Affected
Fuse ESB Enterprise 7.1.0FixedRHSA-2014:045230.04.2014
Fuse Management Console 7.1.0FixedRHSA-2014:045230.04.2014
Fuse MQ Enterprise 7.1.0FixedRHSA-2014:045230.04.2014
Red Hat JBoss A-MQ 6.0FixedRHSA-2014:032324.03.2014
Red Hat JBoss BPMS 6.0CamelFixedRHSA-2014:037103.04.2014
Red Hat JBoss BRMS 6.0CamelFixedRHSA-2014:037203.04.2014

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1049692Camel: remote code execution via XSL

EPSS

Процентиль: 96%
0.28969
Средний

6 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 12 лет назад

The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbitrary Java methods via a crafted message.

nvd
почти 12 лет назад

The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbitrary Java methods via a crafted message.

github
больше 7 лет назад

Apache Camel's XSLT component allows remote attackers to execute arbitrary Java methods

EPSS

Процентиль: 96%
0.28969
Средний

6 Medium

CVSS2