VDB
CVE-2016-4978
CVE-2016-4978
PUBLISHED
Reported by redhat · Published September 27, 2016
The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote authenticated users with permission to send messages to the Artemis broker to deserialize arbitrary objects and execute arbitrary code by leveraging gadget classes being present on the Artemis classpath.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| Maven | org.apache.activemq:artemis-pom | 0, 0 |
| n/a | n/a | n/a, n/a, n/a |
Timeline
- Sep 27, 2016 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 16, 2023 EPSS Score
References
- x_refsource_MISC
- 93142 vdb-entryx_refsource_BID
- RHSA-2018:1448 vendor-advisoryx_refsource_REDHAT
- RHSA-2017:1836 vendor-advisoryx_refsource_REDHAT
- RHSA-2017:1835 vendor-advisoryx_refsource_REDHAT
- RHSA-2018:1449 vendor-advisoryx_refsource_REDHAT
- RHSA-2018:1450 vendor-advisoryx_refsource_REDHAT
- RHSA-2017:3458 vendor-advisoryx_refsource_REDHAT
- RHSA-2017:1837 vendor-advisoryx_refsource_REDHAT
- RHSA-2017:1834 vendor-advisoryx_refsource_REDHAT
- [activemq-users] 20160923 [CVE-2016-4978] Apache ActiveMQ Artemis: Deserialization of untrusted input vunerability mailing-listx_refsource_MLIST
- RHSA-2018:1451 vendor-advisoryx_refsource_REDHAT
- RHSA-2017:3455 vendor-advisoryx_refsource_REDHAT
- RHSA-2017:3456 vendor-advisoryx_refsource_REDHAT
- RHSA-2017:3454 vendor-advisoryx_refsource_REDHAT
- RHSA-2018:1447 vendor-advisoryx_refsource_REDHAT
- [activemq-issues] 20190529 [jira] [Created] (ARTEMIS-2362) activemq-artemis-native-1.0.0.jar is vulnerable to CVE-2016-4978 mailing-listx_refsource_MLIST
- [activemq-issues] 20190529 [jira] [Closed] (ARTEMIS-2362) activemq-artemis-native-1.0.0.jar is vulnerable to CVE-2016-4978 mailing-listx_refsource_MLIST
- [activemq-commits] 20210127 [activemq-website] branch master updated: Publish CVE-2021-26118 mailing-listx_refsource_MLIST
- [activemq-commits] 20210127 [activemq-website] branch master updated: Publish CVE-2021-26117 mailing-listx_refsource_MLIST
…and 7 more