CVE-2025-64408
MEDIUMApache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) through user-controllable URL parameters. These vulnerabilities affect all applications using Causeway's ViewModel functionality and can be exploited by authenticated attackers to execute arbitrary code with application privileges.
- Affected
- [object Object]
- Fixed in
- not stated
- Weakness
- CWE-502
- Published
- 2025-11-19
- Source
- NVD