Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-4974

Опубликовано: 13 июл. 2016
Источник: nvd
CVSS3: 7.5
CVSS2: 6
EPSS Низкий

Описание

Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which might allow remote authenticated users with permission to send messages to deserialize arbitrary objects and execute arbitrary code by leveraging a crafted serialized object in a JMS ObjectMessage that is handled by the getObject function.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:apache:amqp_0-x_jms_client:*:*:*:*:*:*:*:*
Версия до 6.0.3 (включая)
cpe:2.3:a:apache:jms_client_amqp:*:*:*:*:*:*:*:*
Версия до 0.9.0 (включая)

EPSS

Процентиль: 84%
0.02129
Низкий

7.5 High

CVSS3

6 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 9 лет назад

Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which might allow remote authenticated users with permission to send messages to deserialize arbitrary objects and execute arbitrary code by leveraging a crafted serialized object in a JMS ObjectMessage that is handled by the getObject function.

CVSS3: 5.6
redhat
больше 9 лет назад

Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which might allow remote authenticated users with permission to send messages to deserialize arbitrary objects and execute arbitrary code by leveraging a crafted serialized object in a JMS ObjectMessage that is handled by the getObject function.

CVSS3: 7.5
debian
больше 9 лет назад

Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before ...

CVSS3: 7.5
github
больше 3 лет назад

Improper Input Validation in Apache Qpid AMQP 0-x JMS

EPSS

Процентиль: 84%
0.02129
Низкий

7.5 High

CVSS3

6 Medium

CVSS2

Дефекты

CWE-20