CVE-2016-4978

7.2 HIGH
Published: September 27, 2016 Modified: June 15, 2026
View on NVD

Description

The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote authenticated users with permission to send messages to the Artemis broker to deserialize arbitrary objects and execute arbitrary code by leveraging gadget classes being present on the Artemis classpath.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://www.securityfocus.com/bid/93142
Source: secalert@redhat.com
Third Party Advisory VDB Entry
https://access.redhat.com/errata/RHSA-2017:1834
Source: secalert@redhat.com
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1835
Source: secalert@redhat.com
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1836
Source: secalert@redhat.com
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1837
Source: secalert@redhat.com
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3454
Source: secalert@redhat.com
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3455
Source: secalert@redhat.com
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3456
Source: secalert@redhat.com
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3458
Source: secalert@redhat.com
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1447
Source: secalert@redhat.com
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1448
Source: secalert@redhat.com
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1449
Source: secalert@redhat.com
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1450
Source: secalert@redhat.com
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1451
Source: secalert@redhat.com
Third Party Advisory
http://www.securityfocus.com/bid/93142
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry
https://access.redhat.com/errata/RHSA-2017:1834
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1835
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1836
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1837
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3454
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3455
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3456
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3458
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1447
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1448
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1449
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1450
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1451
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://www.blackhat.com/docs/us-16/materials/us-16-Kaiser-Pwning-Your-Java-Messaging-With-Deserialization-Vulnerabilities.pdf
Source: af854a3a-2127-422b-91ae-364da2661108
Technical Description Third Party Advisory

40 reference(s) from NVD

Quick Stats

CVSS v3 Score
7.2 / 10.0
EPSS (Exploit Probability)
6.9%
93th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

redhat apache