Vulnerability Name:

CVE-2015-5254 (CCN-109632)

Assigned:2015-12-28
Published:2015-12-28
Updated:2019-12-17
Summary:Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.
CVSS v3 Severity:9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
6.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-20
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: Apache Web site
CVE-2015-5254 - Unsafe deserialization in ActiveMQ

Source: CONFIRM
Type: UNKNOWN
http://activemq.apache.org/security-advisories.data/CVE-2015-5254-announcement.txt

Source: MITRE
Type: CNA
CVE-2015-5254

Source: FEDORA
Type: UNKNOWN
FEDORA-2015-eefc5a6762

Source: FEDORA
Type: UNKNOWN
FEDORA-2015-7ca4368b0c

Source: CCN
Type: RHSA-2016-0489
Important: Red Hat OpenShift Enterprise 2.2.9 security, bug fix, and enhancement update

Source: REDHAT
Type: UNKNOWN
RHSA-2016:0489

Source: REDHAT
Type: UNKNOWN
RHSA-2016:2035

Source: REDHAT
Type: UNKNOWN
RHSA-2016:2036

Source: DEBIAN
Type: UNKNOWN
DSA-3524

Source: CCN
Type: IBM Security Bulletin 1977546
A vulnerability in Apache ActiveMQ affects IBM Tivoli System Automation Application Manager (CVE-2015-5254)

Source: CCN
Type: IBM Security Bulletin 1981352 (Control Center)
Vulnerability in Apache ActiveMQ affects IBM Control Center (CVE-2015-5254)

Source: CCN
Type: IBM Security Bulletin 2005279 (WebSphere Portal)
Multiple Vulnerabilities affect IBM WebSphere Portal Rich Media Edition

Source: CCN
Type: IBM Security Bulletin 2011304 (Tivoli Components)
OpenSource Apache ActiveMQ Vulnerability identified with Jazz for Service Management (JazzSM) v1.1.3 (CVE-2015-5254)

Source: CCN
Type: IBM Security Bulletin 2012770 (Tivoli Netcool/Impact)
IBM Tivoli Netcool Impact affected by OpenSource Apache ActiveMQ Vulnerability (CVE-2015-5254)

Source: CCN
Type: IBM Security Bulletin 2014179 (Tivoli Components)
OpenSource Apache ActiveMQ vulnerabilities identified with IBM Tivoli Integrated Portal (TIP) v2.2

Source: CCN
Type: IBM Security Bulletin 2014253 (Tivoli Netcool/Impact)
IBM Tivoli Netcool Impact is affected by multiple vulnerabilities in IBM Tivoli Integrated Portal (TIP)

Source: MLIST
Type: UNKNOWN
[oss-security] 20151208 [ANNOUNCE] CVE-2015-5254 - Unsafe deserialization in ActiveMQ

Source: CCN
Type: Oracle CPUJul2017
Oracle Critical Patch Update Advisory - July 2017

Source: CONFIRM
Type: UNKNOWN
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html

Source: CCN
Type: Oracle CPUOct2017
Oracle Critical Patch Update Advisory - October 2017

Source: CONFIRM
Type: UNKNOWN
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html

Source: XF
Type: UNKNOWN
apache-activemq-cve20155254-code-exec(109632)

Source: CONFIRM
Type: UNKNOWN
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680

Source: CONFIRM
Type: Vendor Advisory
https://issues.apache.org/jira/browse/AMQ-6013

Source: MLIST
Type: UNKNOWN
[activemq-commits] 20190327 svn commit: r1042639 - in /websites/production/activemq/content/activemq-website: ./ projects/artemis/download/ projects/classic/download/ projects/cms/download/ security-advisories.data/

Source: CCN
Type: IBM Security Bulletin 0728833 (Sterling B2B Integrator)
Multiple Security Vulnerabilities in ActiveMQ Affect IBM Sterling B2B Integrator

Source: CCN
Type: IBM Security Bulletin 0872142 (Security Identity Governance and Intelligence)
IBM has announced a release for IBM Security Identity Governance and Intelligence in response to multiple security vulnerabilities

Source: CCN
Type: IBM Security Bulletin 6233386 (UrbanCode Deploy)
CVE-2015-5254 Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker

Source: CCN
Type: IBM Security Bulletin 6955033 (Security Directory Integrator)
IBM Security Directory Integrator is affected by multiple security vulnerabilities

Source: CCN
Type: IBM Security Bulletin 7001693 (Security Directory Suite VA)
IBM Security Directory Suite is vulnerable to multiple issues

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2015-5254

Vulnerable Configuration:Configuration 1:
  • cpe:/a:redhat:openshift:2.0:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:apache:activemq:5.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.3.2:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.4.1:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.4.3:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.5.0:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.6.0:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.7.0:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.8.0:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.9.0:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.9.1:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.10.0:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.10.1:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.10.2:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.11.0:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.11.1:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.11.2:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.12.0:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.12.1:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:fedoraproject:fedora:22:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:23:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:apache:activemq:5.5.0:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.7.0:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.6.0:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:apache:activemq:5.11.1:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:websphere_portal:8.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:tivoli_system_automation_application_manager:3.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:tivoli_netcool/impact:6.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:sterling_b2b_integrator:-:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_portal:8.5:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:tivoli_system_automation_application_manager:4.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:tivoli_netcool/impact:6.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:tivoli_netcool/impact:7.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:control_center:5.4.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:control_center:6.0.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_identity_governance_and_intelligence:5.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_identity_governance_and_intelligence:5.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:bi_publisher:11.1.1.7.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:enterprise_repository:11.1.1.7.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:enterprise_repository:12.1.3.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_identity_governance_and_intelligence:5.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_identity_governance_and_intelligence:5.2.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_identity_governance_and_intelligence:5.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_identity_governance_and_intelligence:5.2.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_identity_governance_and_intelligence:5.2.3.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:sterling_b2b_integrator:5.2.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:sterling_b2b_integrator:5.2.6.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_identity_governance_and_intelligence:5.2.4:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:urbancode_deploy:6.2.7.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_identity_governance_and_intelligence:5.2.4.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:urbancode_deploy:7.0.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:urbancode_deploy:7.0.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:urbancode_deploy:6.2.7.4:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.cisecurity:def:577
    P
    DSA-3524-1 -- activemq -- security update
    2016-07-01
    oval:com.ubuntu.precise:def:20155254000
    V
    CVE-2015-5254 on Ubuntu 12.04 LTS (precise) - medium.
    2016-01-08
    oval:com.ubuntu.xenial:def:201552540000000
    V
    CVE-2015-5254 on Ubuntu 16.04 LTS (xenial) - medium.
    2016-01-08
    oval:com.ubuntu.trusty:def:20155254000
    V
    CVE-2015-5254 on Ubuntu 14.04 LTS (trusty) - medium.
    2016-01-08
    oval:com.ubuntu.xenial:def:20155254000
    V
    CVE-2015-5254 on Ubuntu 16.04 LTS (xenial) - medium.
    2016-01-08
    BACK
    redhat openshift 2.0
    apache activemq 5.0.0
    apache activemq 5.1.0
    apache activemq 5.2.0
    apache activemq 5.3.0
    apache activemq 5.3.1
    apache activemq 5.3.2
    apache activemq 5.4.0
    apache activemq 5.4.1
    apache activemq 5.4.3
    apache activemq 5.5.0
    apache activemq 5.5.1
    apache activemq 5.6.0
    apache activemq 5.7.0
    apache activemq 5.8.0
    apache activemq 5.9.0
    apache activemq 5.9.1
    apache activemq 5.10.0
    apache activemq 5.10.1
    apache activemq 5.10.2
    apache activemq 5.11.0
    apache activemq 5.11.1
    apache activemq 5.11.2
    apache activemq 5.12.0
    apache activemq 5.12.1
    fedoraproject fedora 22
    fedoraproject fedora 23
    apache activemq 5.5.0
    apache activemq 5.7.0
    apache activemq 5.6.0
    apache activemq 5.4.0
    apache activemq 5.1.0
    apache activemq 5.0.0
    apache activemq 5.11.1
    ibm websphere portal 8.0
    ibm tivoli system automation application manager 3.2.2
    ibm tivoli netcool/impact 6.1.1
    ibm sterling b2b integrator -
    ibm websphere portal 8.5
    ibm tivoli system automation application manager 4.1
    ibm tivoli netcool/impact 6.1
    ibm tivoli netcool/impact 7.1.0
    ibm control center 5.4.2.1
    ibm control center 6.0.0.1
    ibm security identity governance and intelligence 5.2
    ibm security identity governance and intelligence 5.2.1
    oracle bi publisher 11.1.1.7.0
    oracle enterprise repository 11.1.1.7.0
    oracle enterprise repository 12.1.3.0.0
    ibm security identity governance and intelligence 5.2.2
    ibm security identity governance and intelligence 5.2.2.1
    ibm security identity governance and intelligence 5.2.3
    ibm security identity governance and intelligence 5.2.3.1
    ibm security identity governance and intelligence 5.2.3.2
    ibm sterling b2b integrator 5.2.0.1
    ibm sterling b2b integrator 5.2.6.3
    ibm security identity governance and intelligence 5.2.4
    ibm urbancode deploy 6.2.7.3
    ibm security identity governance and intelligence 5.2.4.1
    ibm urbancode deploy 7.0.3.0
    ibm urbancode deploy 7.0.4.0
    ibm urbancode deploy 6.2.7.4