{"id":"CVE-2020-11971","details":"Apache Camel's JMX is vulnerable to Rebind Flaw. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.x, 3.0.0 up to 3.1.0 is affected. Users should upgrade to 3.2.0.","aliases":["GHSA-hfg5-xpvw-c9x4"],"modified":"2026-05-28T04:04:24.923888089Z","published":"2020-05-14T17:15:12.053Z","related":["CGA-8qfm-5vj9-mch9"],"database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"8.0.0"},{"last_affected":"8.1.0"},{"introduced":"8.2.0"},{"last_affected":"8.2.3"}],"source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:communications_diameter_intelligence_hub:*:*:*:*:*:*:*:*"],"vendor_product":"oracle:communications_diameter_intelligence_hub"},{"extracted_events":[{"introduced":"8.0.0"},{"last_affected":"8.2.2"}],"source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:*"],"vendor_product":"oracle:communications_diameter_signaling_router"},{"extracted_events":[{"last_affected":"13.3.0.0"},{"last_affected":"13.4.0.0"}],"source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:enterprise_manager_base_platform:13.3.0.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:enterprise_manager_base_platform:13.4.0.0:*:*:*:*:*:*:*"],"vendor_product":"oracle:enterprise_manager_base_platform"},{"extracted_events":[{"last_affected":"12.0.0"},{"last_affected":"12.1.0"}],"cpes":["cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:*"],"source":"CPE_STRING","vendor_product":"oracle:flexcube_private_banking"}]},"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/r16f4f9019840bc923e25d1b029fb42fe2676c4ba36e54824749a8da9%40%3Ccommits.camel.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r3d0ae14ca224e69fb1c653f0a5d9e56370ee12d8896aa4490aeae14a%40%3Ccommits.camel.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r45da6abb42a9e6853ec8affdbf591f1db3e90c5288de9d3753124c79%40%3Cissues.activemq.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r52a5129df402352adc34d052bab9234c8ef63596306506a89fdc7328%40%3Cusers.activemq.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r7968b5086e861da2cf635a7b215e465ce9912d5f16c683b8e56819c4%40%3Ccommits.camel.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r8988311eb2481fd8a87e69cf17ffb8dc81bfeba5503021537f72db0a%40%3Cissues.activemq.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r938dc2ded68039ab747f6d7a12153862495d4b38107d3ed111994386%40%3Cissues.activemq.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r9dc2505651788ac668299774d9e7af4dc616be2f56fdc684d1170882%40%3Cusers.activemq.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rb0033c4e9dade1fdf22493314062364ff477e9a8b417f687dc168468%40%3Cissues.activemq.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rc907a3d385a9c62416d686608e7241c864be8ef2ac16a3bdb0e33649%40%3Cissues.activemq.apache.org%3E"},{"type":"ADVISORY","url":"https://www.oracle.com/security-alerts/cpujan2021.html"},{"type":"ADVISORY","url":"https://www.oracle.com/security-alerts/cpuoct2020.html"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2020/05/14/7"},{"type":"FIX","url":"https://camel.apache.org/security/CVE-2020-11971.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuapr2022.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/camel","events":[{"introduced":"363777cc93ab6072cd12d2a231c2165cbc6c0524"},{"last_affected":"9636f69dd42c5b01052875f960fb05d2edc4a8a9"}],"database_specific":{"extracted_events":[{"introduced":"2.22.0"},{"last_affected":"3.1.0"}],"cpe":"cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:*","source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-11971.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}