Логотип exploitDog
bind:CVE-2016-4978
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2016-4978

Количество 3

Количество 3

redhat логотип

CVE-2016-4978

больше 9 лет назад

The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote authenticated users with permission to send messages to the Artemis broker to deserialize arbitrary objects and execute arbitrary code by leveraging gadget classes being present on the Artemis classpath.

CVSS3: 6.6
EPSS: Низкий
nvd логотип

CVE-2016-4978

больше 9 лет назад

The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote authenticated users with permission to send messages to the Artemis broker to deserialize arbitrary objects and execute arbitrary code by leveraging gadget classes being present on the Artemis classpath.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-r9vv-xj4w-g8m8

больше 3 лет назад

Apache ActiveMQ Artemis RCE Via Deserialization Gadget Chain

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2016-4978

The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote authenticated users with permission to send messages to the Artemis broker to deserialize arbitrary objects and execute arbitrary code by leveraging gadget classes being present on the Artemis classpath.

CVSS3: 6.6
1%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-4978

The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote authenticated users with permission to send messages to the Artemis broker to deserialize arbitrary objects and execute arbitrary code by leveraging gadget classes being present on the Artemis classpath.

CVSS3: 7.2
1%
Низкий
больше 9 лет назад
github логотип
GHSA-r9vv-xj4w-g8m8

Apache ActiveMQ Artemis RCE Via Deserialization Gadget Chain

CVSS3: 7.2
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу