Vulnerability Description
Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which might allow remote authenticated users with permission to send messages to deserialize arbitrary objects and execute arbitrary code by leveraging a crafted serialized object in a JMS ObjectMessage that is handled by the getObject function.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Amqp 0-X Jms Client | <= 6.0.3 |
| Apache | Jms Client Amqp | <= 0.9.0 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/137749/Apache-Qpid-Untrusted-Input-DeserialThird Party AdvisoryVDB Entry
- http://qpid.apache.org/components/jms/security-0-x.htmlVendor Advisory
- http://qpid.apache.org/components/jms/security.htmlVendor Advisory
- http://www.securityfocus.com/archive/1/538813/100/0/threaded
- http://www.securityfocus.com/bid/91537Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1036239Third Party AdvisoryVDB Entry
- https://issues.apache.org/jira/browse/QPIDJMS-188Issue Tracking
- http://packetstormsecurity.com/files/137749/Apache-Qpid-Untrusted-Input-DeserialThird Party AdvisoryVDB Entry
- http://qpid.apache.org/components/jms/security-0-x.htmlVendor Advisory
- http://qpid.apache.org/components/jms/security.htmlVendor Advisory
- http://www.securityfocus.com/archive/1/538813/100/0/threaded
- http://www.securityfocus.com/bid/91537Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1036239Third Party AdvisoryVDB Entry
- https://issues.apache.org/jira/browse/QPIDJMS-188Issue Tracking
FAQ
What is CVE-2016-4974?
CVE-2016-4974 is a vulnerability with a CVSS score of 7.5 (HIGH). Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which might allow remote authenticated users with permiss...
How severe is CVE-2016-4974?
CVE-2016-4974 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-4974?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Amqp 0-X Jms Client, Apache Jms Client Amqp.