Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2015-5254
Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the…
Technology
Apache ActiveMQ
CVSS Score
9.8 / 10.0
Affected Versions
5.0.0; 5.1.0; 5.2.0; 5.3.0
Upstream Fix
See upstream advisory
Published
January 8, 2016
OSSeva Coverage
Fixed upstream
Description
Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.
Is your Apache ActiveMQ deployment affected?
If you're running 5.0.0; 5.1.0; 5.2.0; 5.3.0, you need this patch. Book a discovery call to get covered.