CVE-2015-5254

CRITICAL

Apache ActiveMQ <5.13.0 - RCE

Title source: llm

Description

Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.

Exploits (4)

nomisec WORKING POC 15 stars
by jas502n · poc
https://github.com/jas502n/CVE-2015-5254
nomisec WORKING POC 2 stars
by Ma1Dong · poc
https://github.com/Ma1Dong/ActiveMQ_CVE-2015-5254
nomisec WORKING POC 1 stars
by Catherines77 · poc
https://github.com/Catherines77/ActiveMQ-EXPtools
nomisec WORKING POC
by guigui237 · poc
https://github.com/guigui237/Exploitation-de-la-vuln-rabilit-CVE-2015-5254-

Scores

CVSS v3 9.8
EPSS 0.8038
EPSS Percentile 99.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (28)
apache/activemq 5.0.0
apache/activemq 5.1.0
apache/activemq 5.2.0
apache/activemq 5.3.0
apache/activemq 5.3.1
apache/activemq 5.3.2
apache/activemq 5.4.0
apache/activemq 5.4.1
apache/activemq 5.4.3
apache/activemq 5.5.0
... and 18 more
Published Jan 08, 2016
Tracked Since Feb 18, 2026