Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2013-7285

Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been…

Technology

Apache ActiveMQ

CVSS Score

9.8 / 10.0

Affected Versions

5.15.8

Upstream Fix

See upstream advisory

Published

May 15, 2019

OSSeva Coverage

Fixed upstream

Description

Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.

Is your Apache ActiveMQ deployment affected?

If you're running 5.15.8, you need this patch. Book a discovery call to get covered.