CVE-2016-4978
HIGHApache Activemq Artemis < 1.4.0 - Insecure Deserialization
Title source: ruleDescription
The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote authenticated users with permission to send messages to the Artemis broker to deserialize arbitrary objects and execute arbitrary code by leveraging gadget classes being present on the Artemis classpath.
References (20)
Scores
CVSS v3
7.2
EPSS
0.0108
EPSS Percentile
77.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
draft
Affected Products (6)
apache/activemq_artemis
< 1.4.0
redhat/jboss_enterprise_application_platform
redhat/jboss_enterprise_application_platform
redhat/jboss_enterprise_application_platform
redhat/jboss_enterprise_application_platform
org.apache.activemq/artemis-pom
< 1.4.0Maven
Timeline
Published
Sep 27, 2016
Tracked Since
Feb 18, 2026