CVE-2015-5344: Apache Camel
Critical severity, CVSS 9.8. EPSS: 7.1% chance of exploitation in the next 30 days.
The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.
Affected products
- Apache Camel: up to and including 2.15.4; version 2.16.0 only
Published 2016-02-03. Last modified 2026-06-17.