| Vulnerability Name: | CVE-2016-4974 (CCN-114717) | ||||||||||||||||||||||||
| Assigned: | 2016-07-02 | ||||||||||||||||||||||||
| Published: | 2016-07-02 | ||||||||||||||||||||||||
| Updated: | 2018-10-09 | ||||||||||||||||||||||||
| Summary: | Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which might allow remote authenticated users with permission to send messages to deserialize arbitrary objects and execute arbitrary code by leveraging a crafted serialized object in a JMS ObjectMessage that is handled by the getObject function. | ||||||||||||||||||||||||
| CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
4.9 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||
| CVSS v2 Severity: | 6.0 Medium (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P)
| ||||||||||||||||||||||||
| Vulnerability Type: | CWE-20 | ||||||||||||||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||
| References: | Source: CCN Type: Apache Web site Qpid Source: MITRE Type: CNA CVE-2016-4974 Source: MISC Type: Third Party Advisory, VDB Entry http://packetstormsecurity.com/files/137749/Apache-Qpid-Untrusted-Input-Deserialization.html Source: CONFIRM Type: Vendor Advisory http://qpid.apache.org/components/jms/security-0-x.html Source: CONFIRM Type: Vendor Advisory http://qpid.apache.org/components/jms/security.html Source: CCN Type: BugTraq Mailing List, Sat, 2 Jul 2016 02:15:24 +0100 [SECURITY] CVE-2016-4974: Apache Qpid: deserialization of untrusted input while using JMS ObjectMessage Source: BUGTRAQ Type: UNKNOWN 20160702 [SECURITY] CVE-2016-4974: Apache Qpid: deserialization of untrusted input while using JMS ObjectMessage Source: BID Type: Third Party Advisory, VDB Entry 91537 Source: CCN Type: BID-91537 Apache QPID CVE-2016-4974 Deserialization Security Bypass Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1036239 Source: XF Type: UNKNOWN apache-qpid-cve20164974-code-exec(114717) Source: CONFIRM Type: Issue Tracking https://issues.apache.org/jira/browse/QPIDJMS-188 | ||||||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
| BACK | |||||||||||||||||||||||||