VYPR
Critical severity9.8NVD Advisory· Published Feb 3, 2016· Updated May 6, 2026

CVE-2015-5344

CVE-2015-5344

Description

The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.camel:camel-xstreamMaven
< 2.15.52.15.5
org.apache.camel:camel-xstreamMaven
>= 2.16.0, < 2.16.12.16.1

Affected products

2
  • Apache/Camel2 versions
    cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:*range: <=2.15.4
    • cpe:2.3:a:apache:camel:2.16.0:*:*:*:*:*:*:*

Patches

7

Vulnerability mechanics

Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

18

News mentions

0

No linked articles in our index yet.