BlackTreeCVE IntelligenceSAP · 3758101
Linked CVE review
Assess and apply SAP security advisory 3758101
- Linked CVEs
- 3
- Confirmed exploited
- 0
- PoC or lab evidence
- 0
- Maximum CVSS
- 9.9
Confirmed exploitation, public exploit material, EPSS probability and CVSS severity answer different questions. “No confirmation recorded” means the checked sources do not currently confirm exploitation. It is not proof that exploitation has not occurred.
| CVE and description | Severity | Exploit reality | Forecast and access | Remediation |
|---|---|---|---|---|
CVE-2026-40860 Critical technical severity Apache Camel: Unsafe Deserialization of JMS ObjectMessage in camel-jms, camel-sjms, camel-sjms2 and camel-amqpJmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() without applying any ObjectInputFilter, class allowlist or class denylist. Because this code path is reached whenever the mapJmsMessage option is enabled (the default) and Camel acts as a JMS consumer, an attacker able to | 9.8 · CVSS 3.1 · CriticalSource: CISA ADP | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.53% · 74.0th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · NONE user interaction | Within 72 hoursCritical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.Patch available. RHSA-2026:22453: Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 |
CVE-2026-33454 Critical technical severity Apache Camel: Inbound Header Filter Missing in MailHeaderFilterStrategy Allows Remote Code Execution via MIME Header Injection (CVE-2025-30177 Variant)The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filters the 'out' direction via setOutFilterStartsWith, while it does not configure the 'in' direction via setInFilterStartsWith. As a result, when a Camel application consumes mail through camel-mail (for example via from(\"imap://...\") or from(\"pop3://.. | 9.4 · CVSS 3.1 · CriticalSource: CISA ADP | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.03% · 62.7th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · NONE user interaction | Within 72 hoursCritical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.Patch available. Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 |
CVE-2026-40453 Critical technical severity Apache Camel JMS, Apache Camel CoAP, Apache Camel Google PubSub: Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies (camel-jms, camel-sjms, camel-coap, camel-google-pubsub) allows case-variant header injectionThe fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'. The same setLowerCase(true) call was not applied to five non-HTTP HeaderFilterStrategy implementations: JmsHeaderFilterStrategy and ClassicJmsHeaderFilterStrategy in camel-jms, SjmsHeaderFilterStrategy in camel-s | 9.9 · CVSS 3.1 · CriticalSource: CISA ADP | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.89% · 78.9th percentileForecast date: 2026-10-07NETWORK · LOW complexity · LOW privileges · NONE user interaction | Within 7 daysCritical technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 |