Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12527
HistoryJan 15, 2019 - 9:18 a.m.

Remote Code Execution Through Deserialization Attack

2019-01-1509:18:13
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
19

EPSS

0.017

Percentile

87.6%

Apache ActiveMQ Artemis is vulnerable to deserialization attacks. The JMS specification outlines a getObject() method on the javax.jms.ObjectMessage class. The Apache Artemis implementation of this method allows the deserialization of objects, from untrusted sources. There are several places where Apache Artemis uses this getObject() method. These components may therefore be vulnerable to a remote code execution attacks. For this vulnerability to be exploited, the sender of the compromised message needs to be authenticated and authorized in order to send the message to the Artemis broker and affected classes (gadget classes) present on the Artemis class path.

References

EPSS

0.017

Percentile

87.6%