Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

ubuntu логотип

CVE-2016-4974

около 10 лет назад

Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which might allow remote authenticated users with permission to send messages to deserialize arbitrary objects and execute arbitrary code by leveraging a crafted serialized object in a JMS ObjectMessage that is handled by the getObject function.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2016-4974

около 10 лет назад

Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which might allow remote authenticated users with permission to send messages to deserialize arbitrary objects and execute arbitrary code by leveraging a crafted serialized object in a JMS ObjectMessage that is handled by the getObject function.

CVSS3: 5.6
EPSS: Низкий
nvd логотип

CVE-2016-4974

около 10 лет назад

Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which might allow remote authenticated users with permission to send messages to deserialize arbitrary objects and execute arbitrary code by leveraging a crafted serialized object in a JMS ObjectMessage that is handled by the getObject function.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-4974

около 10 лет назад

Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-f38p-mq64-h784

больше 4 лет назад

Improper Input Validation in Apache Qpid AMQP 0-x JMS

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2016-4974

Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which might allow remote authenticated users with permission to send messages to deserialize arbitrary objects and execute arbitrary code by leveraging a crafted serialized object in a JMS ObjectMessage that is handled by the getObject function.

CVSS3: 7.5
6%
Низкий
около 10 лет назад
redhat логотип
CVE-2016-4974

Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which might allow remote authenticated users with permission to send messages to deserialize arbitrary objects and execute arbitrary code by leveraging a crafted serialized object in a JMS ObjectMessage that is handled by the getObject function.

CVSS3: 5.6
6%
Низкий
около 10 лет назад
nvd логотип
CVE-2016-4974

Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which might allow remote authenticated users with permission to send messages to deserialize arbitrary objects and execute arbitrary code by leveraging a crafted serialized object in a JMS ObjectMessage that is handled by the getObject function.

CVSS3: 7.5
6%
Низкий
около 10 лет назад
debian логотип
CVE-2016-4974

Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before ...

CVSS3: 7.5
6%
Низкий
около 10 лет назад
github логотип
GHSA-f38p-mq64-h784

Improper Input Validation in Apache Qpid AMQP 0-x JMS

CVSS3: 7.5
6%
Низкий
больше 4 лет назад

Уязвимостей на страницу