Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2015-5254
Description:Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.
Test IDs: 1.3.6.1.4.1.25623.1.0.809055   1.3.6.1.4.1.25623.1.0.806913   1.3.6.1.4.1.25623.1.0.703524   1.3.6.1.4.1.25623.1.0.809062  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2015-5254
Debian Security Information: DSA-3524 (Google Search)
http://www.debian.org/security/2016/dsa-3524
http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174537.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174371.html
https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2@%3Ccommits.activemq.apache.org%3E
http://www.openwall.com/lists/oss-security/2015/12/08/6
RedHat Security Advisories: RHSA-2016:0489
http://rhn.redhat.com/errata/RHSA-2016-0489.html
RedHat Security Advisories: RHSA-2016:2035
http://rhn.redhat.com/errata/RHSA-2016-2035.html
RedHat Security Advisories: RHSA-2016:2036
http://rhn.redhat.com/errata/RHSA-2016-2036.html




© 1998-2025 E-Soft Inc. All rights reserved.