CVE-2025-64408 describes a critical Java deserialization vulnerability in Apache Causeway, affecting all applications utilizing its ViewModel functionality. Authenticated attackers can exploit this flaw via user-controllable URL parameters to achieve Remote Code Execution (RCE) with application privileges. Rated with a CVSS score of 6.3 (Medium), this vulnerability has a low attack complexity and can lead to limited impact on confidentiality, integrity, and availability. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and community discussion is minimal, users are strongly advised to upgrade to version 3.5.0 to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 3.5.0CPE matchmatch criteria | cpe:2.3:a:apache:causeway:*:*:*:*:*:*:*:* | ||
4.0.0CPE matchmatch criteria | cpe:2.3:a:apache:causeway:4.0.0:m1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.