CVE-2020-11973: Apache Camel

Critical severity, CVSS 9.8. EPSS: 6.8% chance of exploitation in the next 30 days.

Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.

Affected products

  • Apache Camel: from 2.22.0, up to and including 2.25.0; from 3.0.0, up to and including 3.1.0
  • Oracle Communications Diameter Signaling Router: from 8.0.0, up to and including 8.5.0
  • Oracle Enterprise Manager Base Platform: version 13.3.0.0 only; version 13.4.0.0 only
  • Oracle Flexcube Private Banking: version 12.0.0 only; version 12.1.0 only

Published 2020-05-14. Last modified 2026-06-17.