Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-4978

Опубликовано: 23 сент. 2016
Источник: redhat
CVSS3: 6.6
CVSS2: 6
EPSS Низкий

Описание

The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote authenticated users with permission to send messages to the Artemis broker to deserialize arbitrary objects and execute arbitrary code by leveraging gadget classes being present on the Artemis classpath.

It was found that use of a JMS ObjectMessage does not safely handle user supplied data when deserializing objects. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using a JMS ObjectMessage.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Broker 7ArtemisAffected
Red Hat BPM Suite 6hornetqNot affected
Red Hat JBoss BRMS 5hornetqWill not fix
Red Hat JBoss BRMS 6hornetqNot affected
Red Hat JBoss Data Grid 6hornetqOut of support scope
Red Hat JBoss Fuse 6hornetqNot affected
Red Hat JBoss Fuse Service Works 6hornetqWill not fix
Red Hat JBoss Operations Network 3hornetqOut of support scope
Red Hat JBoss Portal 6hornetqOut of support scope
Red Hat JBoss SOA Platform 5hornetqWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1379207Artemis: Deserialization of untrusted input vulnerability

EPSS

Процентиль: 77%
0.01084
Низкий

6.6 Medium

CVSS3

6 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.2
nvd
больше 9 лет назад

The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote authenticated users with permission to send messages to the Artemis broker to deserialize arbitrary objects and execute arbitrary code by leveraging gadget classes being present on the Artemis classpath.

CVSS3: 7.2
github
больше 3 лет назад

Apache ActiveMQ Artemis RCE Via Deserialization Gadget Chain

EPSS

Процентиль: 77%
0.01084
Низкий

6.6 Medium

CVSS3

6 Medium

CVSS2

Уязвимость CVE-2016-4978