HTTP: Apache Camel XSLT Component Java Code Execution

This signature detects attempts to exploit a known vulnerability against Apache Camel XSLT Component. A successful attack can lead to arbitrary java code execution.

Extended Description

The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbitrary Java methods via a crafted message.

Affected Products

Apache camel

References

BugTraq: 65902

CVE: CVE-2014-0003

Short Name
HTTP:APACHE:CAMEL-XSLT-JCE
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Apache CVE-2014-0003 Camel Code Component Execution Java XSLT bid:65902
Release Date
03/24/2014
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Apache

CVSS Score

7.5

Found a potential security threat?