CVE-2020-11971: Apache Camel

High severity, CVSS 7.5. EPSS: 14% chance of exploitation in the next 30 days.

Apache Camel's JMX is vulnerable to Rebind Flaw. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.x, 3.0.0 up to 3.1.0 is affected. Users should upgrade to 3.2.0.

Affected products

  • Apache Camel: from 2.22.0, up to and including 3.1.0
  • Oracle Communications Diameter Intelligence Hub: from 8.0.0, up to and including 8.1.0; from 8.2.0, up to and including 8.2.3
  • Oracle Communications Diameter Signaling Router: from 8.0.0, up to and including 8.2.2
  • Oracle Enterprise Manager Base Platform: version 13.3.0.0 only; version 13.4.0.0 only
  • Oracle Flexcube Private Banking: version 12.0.0 only; version 12.1.0 only

Published 2020-05-14. Last modified 2026-06-17.