Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2013-7285
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been…
Technology
Apache ActiveMQ
CVSS Score
9.8 / 10.0
Affected Versions
5.15.8
Upstream Fix
See upstream advisory
Published
May 15, 2019
OSSeva Coverage
Fixed upstream
Description
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.
Is your Apache ActiveMQ deployment affected?
If you're running 5.15.8, you need this patch. Book a discovery call to get covered.