Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:44077
HistoryOct 31, 2023 - 11:02 a.m.

Remote Code Execution

2023-10-3111:02:01
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
22
activemq
remote code execution
basedatastreammarshaller
openwire protocol
classpath

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H

7.5 High

AI Score

Confidence

High

0.964 High

EPSS

Percentile

99.6%

activemq is vulnerable to Remote Code Execution. The vulnerability is due to BaseDataStreamMarshaller.java as there is no class validation and does not verify that the loaded class is a valid Throwable. This allows an attacker to manipulate serialized class types within the OpenWire protocol, potentially leads to the broker creating an instances of any class available on the systemโ€™s classpath, which can result in Remote Code Execution.

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H

7.5 High

AI Score

Confidence

High

0.964 High

EPSS

Percentile

99.6%