Lucene search

K
ibmIBM439F9EAB478288F16AC5E5D52BACC5DFA9BB4449302EB45AE473376217505124
HistoryJun 17, 2018 - 3:47 p.m.

Security Bulletin: OpenSource Apache ActiveMQ Vulnerability identified with Jazz for Service Management (JazzSM) v1.1.3 (CVE-2015-5254)

2018-06-1715:47:49
www.ibm.com
12

0.039 Low

EPSS

Percentile

92.0%

Summary

OpenSource Apache ActiveMQ Vulnerability identified with Jazz for Service Management v1.1.3

Vulnerability Details

CVEID: CVE-2015-5254**
DESCRIPTION:** Apache ActiveMQ could allow a remote attacker to execute arbitrary code on the system, caused by the failure to restrict the classes that can be serialized in the broker. An attacker could exploit this vulnerability using a specially crafted serialized Java Message Service (JMS) ObjectMessage object to execute arbitrary code on the system.
CVSS Base Score: 7.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/109632 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)

Affected Products and Versions

Jazz for Service Management version 1.1.3

Remediation/Fixes

Principal Product and Version(s)

| Cumulative Patch Level
—|—
Jazz for Service Management version 1.1.3| Cross-Site Request Forgery (CSRF) vulnerability addressed with JazzSM 1.1.3 Cumulative Patch level 5
1.1.3.0-TIV-JazzSM-DASH-Cumulative-Patch-0005

Workarounds and Mitigations

None

CPENameOperatorVersion
tivoli componentseq1.1.3

0.039 Low

EPSS

Percentile

92.0%