CVE-2019-0188
Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed.
- Affected products
- Apache Camel, Json-Lib
- Apache Camel
- < 2.24.0
- Oracle Enterprise Data Quality
- = 11.1.1.9.0
- Oracle Enterprise Manager Base Platform
- = 13.3.0.0, 13.4.0.0
- Oracle Flexcube Private Banking
- = 12.0.0, 12.1.0
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 8.5% (94th percentile)
- Weakness
- CWE-611
- NVD status
- Modified
- Published
- 2019-05-28
CVE-2019-0188 at NVD
No indexed exploits for CVE-2019-0188 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2019-0188 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.