← All CVEs

CVE-2015-5254

critical · 9.8

Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.

9.8
CVSS
38.2%
EPSS (exploit prob.)
98th
EPSS percentile
2016-01-08
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
redhatopenshift2.0
apacheactivemq5.0.0
apacheactivemq5.1.0
apacheactivemq5.2.0
apacheactivemq5.3.0
apacheactivemq5.3.1
apacheactivemq5.3.2
apacheactivemq5.4.0
apacheactivemq5.4.1
apacheactivemq5.4.3
apacheactivemq5.5.0
apacheactivemq5.5.1
apacheactivemq5.6.0
apacheactivemq5.7.0
apacheactivemq5.8.0
apacheactivemq5.9.0
apacheactivemq5.9.1
apacheactivemq5.10.0
apacheactivemq5.10.1
apacheactivemq5.10.2
apacheactivemq5.11.0
apacheactivemq5.11.1
apacheactivemq5.11.2
apacheactivemq5.12.0
apacheactivemq5.12.1
fedoraprojectfedora22
fedoraprojectfedora23

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-5254