CVE-2025-64408
medium · 6.3Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) through user-controllable URL parameters. These vulnerabilities affect all applications using Causeway's ViewModel functionality and can be exploited by authenticated attackers to execute arbitrary code with application privileges. This issue affects all current versions. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
6.3
CVSS
10.8%
EPSS (exploit prob.)
96th
EPSS percentile
2025-11-19
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Weaknesses
CWE-502
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | causeway | >= 2.0.0, < 3.5.0 |
| apache | causeway | 4.0.0 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-64408