← All CVEs

CVE-2025-64408

medium · 6.3

Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) through user-controllable URL parameters. These vulnerabilities affect all applications using Causeway's ViewModel functionality and can be exploited by authenticated attackers to execute arbitrary code with application privileges.  This issue affects all current versions. Users are recommended to upgrade to version 3.5.0, which fixes the issue.

6.3
CVSS
10.8%
EPSS (exploit prob.)
96th
EPSS percentile
2025-11-19
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Weaknesses

CWE-502

Affected products

VendorProductAffected versions
apachecauseway>= 2.0.0, < 3.5.0
apachecauseway4.0.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-64408